Geohot presents an evasi0n7 writeup
geohot.com
geohot.com
> I found nothing sketchy in my reversing, your phones most likely aren't being backdoored by Chinese.
The persistent (and buggy) stage of the exploit used to "untether" (re-exploit on reboot) and patch the OS is obfuscated. That's where a backdoored exploit would be if there was one anyway.
I think it's unlikely the evad3rs actually included a backdoor in their payload, but the way they handled their release was still silly enough that I won't install it. iOS jailbreaks are all taken on faith (after all, nobody but them knows what's in that obfuscated untether/patch binary) and they didn't do a lot to build any.
They agreed to bundle an app store who's only purpose is piracy (0xabadidea and Paul Haddad worked to remove their piracy system previously) without in the slightest wondering what it would be used for. From what I've read there's still bits of the Chinese scumware installed when you jailbreak in another country, and given the opinion of the Chinese company involved.. I wouldn't put it past them.
I truly hope that geohot or another skilled developer repackages their jailbreak with a copy of MobileSubstrate that actually works and a Cydia build that's built properly by saurik. The evad3rs have completely lost any trust they have, and from pod2g's tweets they're extremely aware of how badly they fucked this up.
• evad3rs released an iOS7 jailbreak unexpectedly due to a leak
• it became apparent that it bundles some Chinese piracy store with no other legitimate purpose [0]
• information is made public that the evad3rs were paid $1M USD to include the piracy store
• evad3rs say they weren't aware it was for piracy (and never bothered to check)
• evad3rs aren't even sure if the Chinese bundle is malicious, it sends home encrypted something [1]
• evad3rs remove the Chinese bundles from their server and activate their kill switch [2]
• pod2g promises to release a clean jailbreak [3]
The end result is that the jailbreak ruined the trust of the community by including crapware and possibly malware, enabling mass piracy, ultimately not even bothering to check the binaries that they were paid to include. They've burnt Geohot's exploits for a 7.1 jailbreak, as the release timing means that they will be patched by Apple and be completely useless in the future. The jailbreak they released is worthless for the moment due to them not bothering to include the proper Substrate releases from saurik.
[0]: https://twitter.com/pod2g/status/414810029376933889
[0]: https://twitter.com/pod2g/status/415114461473964032
[0]: https://twitter.com/pod2g/status/414820772931067905
[1]: https://twitter.com/pod2g/status/415116127292108801
They've burnt Geohot's exploits for a 7.1
jailbreak, as the release timing means that
they will be patched by Apple and be completely
useless in the future.
The jailbreak they released is worthless for
the moment due to them not bothering to include
the proper Substrate releases from saurik.
This all comes through at a curious moment, when Apple announces a massive deal that opens up a truly vast Chinese market for them.http://www.reuters.com/article/2013/12/23/us-apple-china-mob...
So, like, what if Apple and the Communist Chinese have colluded to prevent jailbroken iPhones in China, as part of the deal? Mostly because we're already talking about buy-offs and leaks with curious timing... So, somewhere along the line Xi Jinping and Tim Cook have a little sit down, and shortly thereafter, members of PLA Unit 61398 approach evad3rs on IRC all like:
"the people of china need iPhones, but the chinese
government, needs them to be 'safe' [wink]...
if we give you certain... packages, mr. hotz is uh...
known to have, maybe eh... well ...listen, i'm just
going to come out and say it... geohotz needs to
take a fall. here's a retainer, see what you can do."
</hand-wavey-magical-thinking>> This journey stops at root for now, since the /evasi0n7 binary is supa obfuscated good.
A few of those are created by the jailbreak but most are core parts of the system.
It doesn't seem like it'd be incredibly hard to remove those symlinks. Although Apple would probably favor fixing the bugs that allow malicious symlinks rather than remove symlinks from their file system driver (the horror!)
Plus, old binaries break all the time due to incompatible software or hardware changes (AVFoundation, GL shaders, UDID bans, etc.).
And new builds certainly get new requirements imposed (forced minimum SDK version etc)
[1]: http://geohot.com/mt.jpg [2]: http://images.apple.com/iphone/compare/images/compare_iphone...
The keyboard is iOS 6 styled because the app hasn't been compiled for iOS 7.
Nothing out of the ordinary here.