Injecting malware into iOS devices via malicious chargers
blackhat.com
blackhat.com
So yes, they are installing unsigned software through USB on an iPhone by plugging it into a USB socket in a computer. That is just normal jailbreaking, and has been done forever, isn't it?
On another note, I've been amazed by the number of people who let others plug phones into their computer for a quick charge.
I'll let people borrow my wall charger if I'm sitting there but no one plugs anything into my computer.
I believe the same, including vice versa for that matter. (That is, I would never plug a phone into somebodies computer.)
The researchers are using a Beagleboard device for the exploit. Based on what they've said to the press so far, it sounds like a no-interaction tethered jailbreak (if it's truly functional on all Apple devices) or at best an untethered jailbreak on limited Apple devices.
If this presentation is claiming the ability to install software on ALL non-jailbroken Apple devices running the latest OS version that survives a reboot of the device (once it's detached from the charger), then that's potentially worth more than any "malicious USB charger" talk (since the jailbreak community is currently unable to to do this).
This is, of course, insanely unlikely today. But in a few years, when everything has a 1GHz ARM core and an internet connection, we very well might start seeing malware that jumps devices and infects entire households.
That's the bad part! Somebody screwed up big time if the package manager does not insist on user permission for installs that are initiated without proper authentication token. (Google does this for app installs from store over the Internet - but you and your device both need to be obviously logged in to your Google account for that to work.)
> The vulnerability involves discrepancies in how Android applications are cryptographically verified & installed, allowing for APK code modification without breaking the cryptographic signature; that in turn is a simple step away from system access & control.
Bugs happen.
Yeah that's the point - having a closed device doesn't magically make it more secure. FTA -
> Apple iOS devices are considered by many to be more secure than other mobile offerings.
Also the Android bug is different class - the vulnerability description doesn't really say what is required to be able to modify the APK in transit which is key to being able to exploit the bug. From the sparse description it sounds like somebody needs to do a SSL MITM or the user needs to install an APK from untrusted source and get fooled into thinking since its signature matches it must be from the original author. (Just to be sure failing to detect APK modification is horrible but whether or not it is easily exploitable is a different thing altogether.)
In iOS charger case - it's clear that it's just a matter of plugging in your device to a malicious charger.
Edit: not quite a dongle, but something like http://amazon.com/dp/B009W34XMM should fit the bill, no?
Edit 2: http://amazon.com/dp/B0042LF23I looks exactly right, although build quality appears to be an issue.
This sounds like weasel words (eg, "some people believe"), and even if it's true, why does this misconception exist?
What happens in this situation? Would Apple try to get them not to give the talk? Will Apple patch the problem in the meantime? Does anyone get sued?