Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
zdziarski.com
zdziarski.com
http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS...
For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
> iPhone Configuration Utility 3.6.2 for Windows
BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.
They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's just lip service and pure marketing.
At lower levels you have a vestigial democracy and true "independent" free enterprise, but when you get to be a company the size of Apple you are too big to blend in with the ordinary civilian economy. Getting that large results in immediate audience before the king, which in America is the military/intelligence shadow state. I'd be very surprised if one can ascend to the billion-dollar stratum in America without some very interesting closed-door meetings with strict NDAs. I'm also sure that all kinds of next-level stuff kicks in when you start to become a major international corporation that does heavy business overseas, as Apple is.
There are endless forms of soft power that can be brought to bear against a large company, especially a publicly traded one. You've got the standard issue tax evasion practices of every major corporation for starters. Don't want to help us spy on users? How about a high-resolution IRS audit and some "offshore banking reform" specifically targeted at you? Then there's anti-trust, which is obviously selectively enforced. Does Apple have anything that could be called a monopoly or a monopolistic business practice?
For example, there are alternatives to Dropbox that do this: http://www.theguardian.com/technology/2014/jul/17/edward-sno...
Lavabit shown the government can demand installation of their own surveillance equipment on a company's premises to gather that data themselves. I wonder if they could make the same demand on a company like Apple to install their own back doors if Apple decided not to collect that information themselves.
I don't know where this ends, but I suspect it ends up with lots of computer programmers rotting in jail, others going underground and everyone just accepting that they live in a totalitarian state run by the military, which constantly brainwashes its children to believe they live in the best country in the world.
If users really wanted it and clamored for it and showed a clear market preference for secure and privacy-respecting companies, then you might get somewhere.
What would they buy, today, in order to "show a clear market preference"?
It's a bit difficult to show statistical evidence of people making choices which are unavailable to them.
A 3rd party audit of the source would go some way toward building that trust, but falling short of a publicly available code-base allowing independent verification, I doubt it would be enough.
Just create a profile with the restrictions, then follow the instructions at: http://support.apple.com/kb/HT5833
(Edit to add: It's actually unclear if the non-pairing restriction gets applied when using this method, it doesn't seem to get listed in the profile details once on the device)
Is this not the case?
The slides mention a way to bypass pairing, but I don't think ever mentioned how.
I believe the device still needs an AfterFirstUnlock key to decrypt the escrow keys, so a cold-booted device wouldn't be accessible even if it was paired.
Discriminating by MAC addresses would not help at all. MAC addresses are trivial to spoof, even though they are "in hardware".
It would be cool if we had a standardized trust-on-first-use cryptographic authentication model for wireless APs, like we do with SSH right now. You connect to the AP, it sends you its pubkey, your phone says "Do you want to trust AP with key AB:CD:BE:EF...". The discriminating paranoid person can choose to make sure this is the right key hash, and the average person gets at least limited protection from later AP spoofing attacks.
Of course, once you have the AP password there's a lot you can do to the network traffic anyway, but it'd still be nice if the computer would pop something up and say, "The configuration of this device does not match the known configuration - do you still want to connect?"
According to the other comments, apparently something like this is already a feature in WPA2, so evidently it doesn't break down too much.
This was intentionally architected for exploit.
So, if you are in a situation where you can expect that your device will be accessed (e.g. crossing the US border), switch it off ahead of time.
[1]- http://www.theguardian.com/world/2014/jul/06/tsa-cellphones-... [2] - http://www.forbes.com/sites/kashmirhill/2013/02/21/the-priva...
Would bluetooth or iBeacon or Wifi be used with that, or does it need a cable, or actual button pressing, for example?
"STOP RESISTING, WE WANT TO TRACK YOU" (iBeacon)
The good news is that it appears to be opt-in. In most, if not all, instances a user needs to install an app and enable location services before the iBeacon will trigger anything. No app listening for a particular beacon or set of beacons, no problem.
Of course, there could also be malicious code running on the phone, installed by the government or spies, that could silently record everything. That could work now with gps, voice and video recording, wifi network positioning, etc. iBeacon is just one more set of data to collect.
Linking directly to the pdf would go against what the author says he wants there.
So much for iMessage security. Also, ProtonMail works much in the same way (central key management), for anyone wondering, so it should be vulnerable to the same type of attacks.
Though I see no reason why clicking a link should result in the zoom level changing, so it does seem like a bug.
As somebody else mentioned, you can use the arrow/triangle to display the regular viewer toolbar, and zoom out. This is obviously not ideal, but there's not much else that can be done until a fix comes from pdf.js upstream, I suppose.
As mentioned below, authors have to pay publication fees. Most journals are for profit and closed-access, though this is starting to change somewhat. Somewhat ironically, being published in these journals is a prerequisite for how researchers actually do get paid: by grants, usually taxpayer funded.