Tiny device is sending updated iPhones into a never-ending DoS loop
arstechnica.com
arstechnica.com
I know I'm preaching to the choir here on this site, but as a reminder, the tool only exposes a bug that was already there. It's an exploit for an existing problem. I'm glad that this bug is getting press now so maybe it'll get fixed. Without the public visibility, only the bad guys would have this ability.
And as another reminder, an exploit that can reboot a device might be able to leverage that memory leak, null dereference, or whatever else to do more than just crash it.
A bank robber, terrorist or totalitarian state could benefit significantly from bringing down all cell phones in the area for a few minutes (or even just crashing them in a loop as they boot up).
Such an odd question.
If I'm home, I'm using a computer or tablet, so I don't even turn Wi-Fi on my phone there.
People don't seem to think this stuff through. Although to be fair, most people have no idea they're wasting power, and Apple defaults everything to ON and makes it a PITA to turn this shit off. They even put fake "on/off" controls in "Control Center" that only toggle BT and Wi-Fi TEMPORARILY. Offensive disregard for the user's choices.
I suggest telling Apple to permanently respect the user's on/off choices no matter where they make them: https://www.apple.com/feedback/iphone/
Bluetooth uses very very little power. Think about it. While I don't know the specifics of the iphones BT unit, let's take the Airpods and assume it's similar . They have about a 25mah battery per earpiece (from what i gather from a 3 second search) and they last about 5 hours. So 100mah per 20 hours. Your iphone, let's say, has 3000mah battery. So in 20 hours BT would use 100/3000 pct of your battery in that period. And that's actively using it.
It's really not worth the effort to bother toggling it.
Now, if you still want to, well that's what automations are for.
I don't see why a toggle should require "automation," but it doesn't matter in my case because it's basically never necessary.
Those who don’t use it, like you, quickly discover the actual way of disabling it. It’s good UX design that aligns with most user’s preferences.
The change removed functionality that was previously available: quick access to the real on/off toggles for these functions. There's a page in Settings devoted to "Control Center." I would have no problem with it if there were a temporary/permanent option there for these toggles, even if Apple defaulted them to the current (temporary) behavior. Then everyone's preference would be served.
It sucks that you have to deal with it for your minority case, but that's just the way things are. There are work-arounds, but you clearly don't want to try any of those. You're prerogative.
And Wi-Fi is more efficient than cellular. It's best to use that as much as possible.
Wi-Fi uses less energy than LTE/5G.
> Although to be fair, most people have no idea they're wasting power, and Apple defaults everything to ON and makes it a PITA to turn this shit off.
Because the vast majority people are OK losing < 2% of their battery life in exchange for the convenience of not having to turn all this shit on every time they want to use their headphones, listen to music in their car, cast something to their TV, etc... Hell, things like smart watches wouldn't even work with this approach.
I don't have to turn any of this shit on. If I want to listen to music, I use the headphone jack or dock connector. I have a real watch, so no issue there. And I never cast to my projector because casting sucks ass, so I use a Shield.
This is not true, because both cellular and wifi connectivity do not have a fixed energy cost. That is determined by both utilization and reception quality.
When you are on WiFi with a smartphone, cellular utilization goes through the floor because nearly all utilization is moved to your more energy efficient wifi connection. Even more so if your carrier supports WiFi calling.
I can prove this in my own house. When I turn WiFi off on my phone for whatever reason and forget to turn it back on before the end of the day, my battery drains noticeably faster.
The things you say were true 15 years ago. But technology has changed and improved tremendously since then.
But all fans are replying: your living room consumption is less than your bed room one.
Sad.
Is it that they don't read, or that they're so eager to prove their inapplicable "point?"
If I am at home, I'm not using the phone except for actual phone calls. It easily lasts all day on cellular standby, and I don't have to remember to turn Wi-Fi off if I'm going to be out for a good portion of the day. I can also charge the phone right in front of me on my desk where I am most of time during the day.
These things are true today, right this minute.
Also: mobile data uses way more energy than Wi-Fi.
I'm sure there have been efficiency improvements over the years, but it's still needless power consumption.
Also Wi-Fi calling appears to be off by default. Thanks for bringing it up, though. I might try it next time I'm in another country; if you switch SIMs on an iPhone, it loses all association between people's phone numbers and their entries in your contacts. Yes... the iPhone can't handle travel, 16 years in. ¯\_(ツ)_/¯
"You're posting too fast. Please slow down. Thanks."
Then why was the Reply button enabled, and why does this rudeness persist year after year?
Of course it will get fixed. Apple fixes bugs _if_ the exploits are made public. /s
It's another thing that Apple confuses people with disabling Bluetooth. I always need to go to settings -> Bluetooth to really turn it off instead of using this pull-down menu. I assume many non-technical people don't understand this difference. So it seems like a violation of UX principles that only makes users feel to be in control.
I hate as much as you do that I can't just turn off BT (nor WiFi!) from the pull-down menu.
But at least on current iOS (17.1), when you "turn off" the BT a message pops saying "disconnecting BT devices until tomorrow"). Ditto for Wi-Fi. Also, when "disconnected", the icons don't look like the others when they are "off" (white background instead of dark gray). They actually look like other icons in the control center when they're turned on! Like the battery saver or flashlight.
They also change to a different icon (barred BT symbol and fully dark) when you switch off BT in the settings.
I'm pretty sure this has been the behavior for a while, since my older iPhone 7 had it too, and was stuck on iOS 15 IIRC.
2. Create shortcut in the "Widgets" folder, which simply runs one action: "Turn Bluetooth Off"
3. Long press home screen to add widget, then select shortcuts widget
Also, the notifications trigger on Windows aswell.
It certainly doesn't go through the internet. I suspect it is direct ipad to iphone communication. I'm going to turn Bluetooth off tonight and see if it goes away.
Tell Apple to PERMANENTLY respect the user's choices when turning BT and Wi-Fi on or off, no matter where they do it: https://www.apple.com/feedback/iphone/
And another good reason: Despite some improvement Apple seems to have made on this issue over time, the phone will still connect to "free" Wi-Fi that has no Internet connectivity as you roam around.
Apple is respecting the choice of the majority of it's users who simply want to disconnect all devices temporarily in order to solve an immediate problem. Nearly all the time, Apple's users want BT (and WiFi) ON.
That’s still not good of course, but the headlines makes it sound like the phone is getting bricked, which is not the case.
IMO the term should be reserved for firmware faults or the levels below. Wikipedia gives a pretty good definition: https://en.m.wikipedia.org/wiki/Brick_(electronics)
I just tested this on my own phone, saw my own Apple ID, and screenshotted it for posterity.
> [the attacker was] using a Flipper Zero device with custom firmware to send a combination of Bluetooth low energy (BLE) alerts to nearby iPhone handsets running iOS 17.
> If you have an iPhone running iOS 17, then the only reliable way to protect against the pop-ups and crash attack is by disabling Bluetooth.
Holy crap ... this means that it probably happened to many other people too.
Unless this was a train going to a security conference.
[1] - https://arstechnica.com/security/2023/11/flipper-zero-gadget...
Apple's aura: Perfect security & privacy
Apple's reality: Overall less-crappy security & privacy than its leading competitors
For a premium brand seeking to maximize profit, this makes perfect business sense. And Tim Cook is pretty good at both the "business" and "profit maximizing" stuff.
Worth noting: The business models for Apple's largest competitors should also motivate them to care greatly about security* and privacy*.
*Excepting the obvious "private" root holes, for their own exclusive use.
If it were me, knowing nothing about the inner details of iOS, I would apply some kind of rate limit or throttling on incoming BT connections and allow the user to ignore repeated incoming connections. It would be not unlike trying to download multiple files from the same website, which usually triggers a "do you want to allow $site to download multiple files?" prompt.
Maybe I'm naïve, but this seems trivial to prevent.
A rate-limit will turn a serious DoS (device crashes) to a very minor DoS (may struggle to pair a new device or get notifications from nearby devices).
I'd be a lot cheaper to get a bunch of those, versus one flipper zero.
https://www.digikey.com/en/products/detail/stmicroelectronic...
I would really like a flipper zero clone though.
But it also makes them liable; messing with other people's tech like this can be construed as attempted hacking. What they were doing was NOT "white-hat hacking", that's the author who reproduced the attack in his own home on his own device.
Need to do critical patient care while commuting? Surely you will have made sure to bring a dumb phone with you as backup, if you are really that critical a resource (after all, your battery might be dead, someone might have stolen your fancy Iphone, etc.).
Time sensitive family issue? What if you turned your phone off to read a book? Are you the asshole now? The train driver might have been stopped at a red signal in the Schipholtunnel; not much of a chance of getting a phone signal there. Is he now endangering people by depriving them of their umbilical uplink?
What if the time sensitive family issue happened while you had your phone turned off for some intimate private time with your partner? How will you ever forgive yourself?
The key takeaway here is to understand that there is no such thing as being available all the time. So don't expect it, and don't feel guilty about not providing it.
There are all plenty more of those convoluted minimal chance scenarios you can come up with, but these hold true for anything people around you do.
Got robbed and murdered? And you only had a deadbolt on your door? Surely you couldn’t be such an idiot as to not have a dual layer steel security door, could you?
Got in a car accident because someone pulled out in front of you? And you were going the speed limit?! What a buffoon. You’re insane to be traveling above 20mph on any roadway, because someone could pull out in front of you at any moment and if you’re smart like me, and not a total doofus, you’re always on your toes.
Got food poisoning at a restaurant? Well if you were smart you’d have asked to see the expiration dates on all their ingredients and observed the kitchen’s methods VERY closely. Make sure you also visit each supplier to observe their hygiene practices, and of course each party who touches each product along the supply chain. Anything short of that is outright negligence on your part.
I’d rather we don’t degrade ourselves into a low trust society due to some abstract desire for “resilience” and instead we just put people in jail to deter people from harming others without their permission.
Imagine if [adversary] spends time finding a zero-day in iOS, Android, Linux, Windows, and MacOS, and releases a worm which bricks every computer it gets on (e.g. overwrites every firmware with something maximally malicious). That's within the scope of capability of many world governments.
What happens?
Do people in hospitals die? Does out infrastructure collapse? Or do things keep ticking on, somehow?
Tools like Chaos Monkey intentionally introduce more errors under normal operating circumstances in order to make systems more robust in extreme ones. This is a real-world analogy.
For something like this on a train, it's a question of value systems. I can't bring myself to _have_ a value system which makes this okay for me to do something similar, but I can see rational value systems which would allow that (e.g. hedonistic utilitarianism). It's the trolly problem.
All the examples you gave, in contrast, are just victim-blaming. There is no greater good.
By my value system, though, what I would like to see are similar tests done planfully and intentionally. In the abstract, if a federal government took down the internet and cell phone networks for eight hours, or we had planned power blackouts, or similar, I'd be fully supportive. That would require organizations to build in the right types of resiliency. I understand that's fully impossible in the kinds of political systems we have. But in the right political system, I'd like to have a government which works to make us resilient to those kinds of extreme events.
Here you go:
* You need steel security doors because we should be resilient to crises and broad security threats. You don't know when there will be a major gang war, a neighbor with a psychotic break, a government breakdown, or a ground invasion. It's just better to have steel security doors because there are all sorts of real risks that they mitigate.
* You need to drive slowly because some day someone will pull out in front of you, even by accident! Accidents like that happen hundreds or thousands of times per day, so it's frankly insane not to be prepared for it.
* You need to check all your restaurant's ingredients because someone will forget to throw out the milk one day. We need to be resilient to this because it's certainly going to happen on occasion, and the right way to achieve resilience is to shift that burden onto end users, or at least to continually poison end users until they demand action from food regulators that we have a 100% foolproof system to prevent bad milk from ever making it into a restaurant meal.
N.B. The comparison to Chaos Monkey is the false analogy. People run Chaos Monkey on their own infrastructure. And yes, if you run a tool like that on someone else's infrastructure without their permission, you're the asshole.
The core issue here is _systemic risk_ and _systemic resiliency_. The risk profile of driving does not change. By driving a car, I expect a risk of 1.5 deaths per 100 million miles driven. We all agree that's a reasonable risk profile.
On the other hand, rare events are things like natural disasters, wars, plaques, asteroids hitting the planet, and so on. Day-to-day decision-making does very poorly for preparing us for those risks.
> And yes, if you run a tool like that on someone else's infrastructure without their permission, you're the asshole.
No. This is wrong.
Things like bug bounty programs were created precisely because whitehat and grayhat hackers made us more resistant to blackhat hackers. If someone tries to compromise my bank's infrastructure _with the intent of surfacing vulnerabilities and without intent of stealing my money_, that might be bad for quarterly profits and my bank might not like it, but it's _good for me_.
Free markets push towards low resiliency by offloading risks onto consumers. Behaviors like this change market dynamics in positive ways.
> bug bounty programs
Who decides whether to operate a bug bounty program and the parameters of said program?
Apparently not....
> So if someone pulls up alongside you at 80mph on a highway and remotely disables your vehicle without your prior consent and you crash into a barricade and your entire family dies, we can just take note of the threat vector and find comfort in the fact that maybe an auto manufacturer will harden their cars against future risks. Makes a ton of sense.
A better example: Someone casually remotely disables all cars in parking lots. They need to be unbricked, which is a month-long process. The outcome is cars are built with security built in. That prevents a terrorist attack six months later where someone was plotting to disable thousands of cars on highways in the way you described.
Cost: Hundreds of parking lot vehicles disabled, with a range of (very real) consequences, such as missing job interviews, missing school pickups, missed medical appointments, etc.
Upside: Dozens of lives saved (but since this never happens, it's abstract lives)
It's very much the trolley problem. It's of course possible to set up absurd trolley problems (pull a lever, kill 5 people instead of 1, rather than the other way around, as you're doing).
People have different answers to the trolley problem.
If you like trolling people you can just say it. No need to make up this "no dude I'm actually helping you defend against a maybe-terrorist attack!"
Yeah, it's like a trolley problem where you tie both sets of people to the tracks and put the trolley in motion. Brilliant.
It's a lost cause.
I, and many others, have the ability to understand value systems we don't share. It would be a good skill to consider developing, in an increasingly diverse world.
I understand and value all of these things. What I'm explaining to you is the ridiculously, ridiculously obvious point that responsible redteaming, chaos engineering, or bug bounty pursuits do not put innocent bystanders at risk. And if you do put innocent bystanders at risk, you are an asshole. Sure, I get that some people have value systems that dispute this, and I'm perfectly comfortable saying those value systems are not worthy of respect.
Intelligence isn't thinking so hard and so abstractly that you can't identify antisocial behavior and inflicting harm on innocent people for very likely zero actual practical societal gain. That's just, again, a convoluted excuse for being an asshole.
It's not a trolly problem, because the 5 people might be on the track but the 1 person is 200km down the track.
Bluetooth has always been leaky, but apart from being trapped on a train it's mostly mitigated by being able to walk away. It's not something techs are un-aware of.
Also.. 99% of the people on the train wouldn't have any idea what's going on. Calling tech support later would have zero affect. So it's not highlighting the issue to anyone who could remotely address it.
The dongle dude here was just being a jerk because he could. Playing loud music would have been about the same. "I'm going to take joy in confusing/annoying others."
What do you do when your phone gets stolen or simply breaks? Complain loudly at the very least, and have a backup in place (but I'm sure you do).
Also note that there are people that have such sensors and insulin pumps connected in a feedback loop. I don't personally but this exists. There also exists a small open source scene around that topic. Examples are https://openaps.org/ or https://nightscout.github.io/
> Your life should not depend on your phone working
My life as diabetic depends on many, many variables. Theoretically, all it needs is an incorrectly labeled meal to do serious harm. Or the delivery guy transporting my insulin didn't maintain cooling. I can only do so much and still live a life without constant fear. While this may sound dangerous to you, this way of measuring your blood glucose is extremely liberating for diabetics. The alternative is just so much worse.
People can die these days if their technology fails. They might not have a better alternative because they can't afford it or it hasn't been invented
Teaching someone a lesson or educating society sounds like a line from a villain from a Bond movie. A sociopathic villain. You are making comments that a sociopath would make.