Advanced iOS virus targeting Hong Kong protestors
reuters.com
reuters.com
https://www.lacoon.com/lacoon-discovers-xsser-mrat-first-adv...
Also worth noting is that they don't have an attack vector for it at present or any evidence it's been deployed. Seems like an 'in development' version that was latent on the control servers, since you have to jailbreak and get the package through Cydia.
https://code4hk.hackpad.com/Fake-Code4HK-Mobile-App-HQXXrylI...
http://www.scmp.com/news/hong-kong/article/1594667/fake-occu...
http://technode.com/2011/05/03/around-35-percent-of-ios-devi...
If you can trojan one in three iphones that's a hell of a severe security issue.
It should be a known risk. I imagine many people don't know (friend told them "this is how you install this weird thing", "this lets you customize icons", "this lets you get apps for free"), but this is the purpose of jailbreaking.
1. Piracy. Apps are expensive on iOS, but Hong Kong loves brands. Having an iPhone is a fashion symbol. Also, access to pirated content (video/music) is a big deal in HK; content is often expensive or unavailable in the region. Content piracy apps, such as BitTorrent clients, Baidu music downloaders, and some MKV-friendly video players, are only available after jailbreaking.
2. Carrier unlock. iPhones sold in Hong Kong are carrier-unlocked, but imported iPhones are often carrier-locked. To force a carrier unlock, you must jailbreak your phone. As a result, a lot of iPhones in HK are either jailbroken to allow carrier unlock or use hardware-based SIM card hacks.
3. Tethering. In HK, most data plans did not allow for free tethering (at the time I was there). Jailbreak allows "illicit" tethering that uses the same data plan, without informing the carrier about how the data is being used.
So, don't assume that jailbreakers are necessarily ignorant.
It's unfortunate that jailbreaking comes with non-obvious security compromises.
> It's unfortunate that jailbreaking comes with non-obvious security compromises.
The 'dangers' are pretty obvious in my opinion. I might be biased though, as I'm a developer, which most people are not.
And when you actually exploit this weakness, next phase is installing apps that can exploit your whole phone.
Back in time I was keen on jailbreaking my device, because I wanted to see bash prompt and do whatever I want with it, but nowadays I left this for non-used devices that I have. I'm pretty concerned with security after the whole NSA revelations and I believe my device is more secure if it's not jailbreaked.
If someone is able to break that chain of security, then that demonstrates a weakness in security.
The question then becomes how easy is it for an attacker to break that chain of security, and is the jailbreak remotely exploitable.
But as the saying goes, "With freedom comes responsibility."
Chinese is a programming language?
but I doubt the author meant it like that.
Or maybe he meant "written in China".