HNHacker News
TopNewBestAskShowJobs

mrex

135 karma · joined July 12, 2022

submissionscomments
mrex··on Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
TLS is transport encryption, not a content signature.

Ideally, I'd like to see every resource being served along with a signature verifying its authenticity, origin, and suitability for public consumption.

Users would then be empowered to make the decision whether we wanted to interact with a resource that does not offer these protections, and assume the risk, or simply refuse to load any resource that doesn't positively identify where it's coming from, who made it, and who certifies it as worthy of your consumption.

mrex··on Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
>This will be instantly defeated by benchmarking the js performance.

How common is this behavior for non-malicious websites that a Lockdown mode user is likely to use? It seems to me that if you're loading malicious content from a site controlled by foreign intelligence services, you're probably done whether Lockdown is enabled or not. Preventing more casual profiling from common logs likely to be strewn about in CDNs, etc. is still an important level of protection, I'd argue.

mrex··on Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
How realistic is an "advanced fingerprinting attack", though?

I think the more realistic threat model here is presented by ad networks and major websites doing typical types of browser fingerprinting, like canvas, fonts, etc. as well as possibly some of the techniques mentioned in the article here, like webGL, JIT JS, etc.

In that case of a limited number of trusted sites that we focus on ensuring compatibility with, spoofing is easier, because we can pay a lot of attention to ensuring that our "middleman" fixes the errors introduced by spoofed client-to-server communications.

Some technologies like WebGL will simply never work on a spoofed site, of course. But for the very limited number of sites when users lose important functionality, they can just turn off Lockdown mode.

If a Lockdown'd phone habitually patronizes malicious websites, the protection will never be enough anyway. So we shouldn't worry about protecting against being fingerprinted by a very malicious website - Lockdown users must simply avoid these, with or without a fingerprinting vulnerability!

mrex··on Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
Ways to counter fingerprinting:

Offer a spoof mode, make the Lockdown mode browser look to external websites like it isn't in Lockdown mode. Tricky but doable with some site breakage that can always be fixed by disabling Lockdown mode for sites a user trusts.

Convince as many people to use Lockdown mode as possible. I, for one, don't see any reason NOT to enable Lockdown mode on all my devices. Do you need iMessage URLs sent by randoms to load remote content without your consent?

Above all, lets begin to consider signed web content..

mrex··on Analyzing iOS 16 Lockdown Mode: Browser Features and Performance
But that's only a single application. Lockdown Mode affects the operation of the entire OS, and all applications that use certain iOS features.
mrex··on Stereokit – Open-source mixed reality library by Microsoft
I would be beyond shocked if Apple's VR set doesn't include a Thunderbolt port.
mrex··on FCC: TikTok is unacceptable security risk and should be removed from app stores
The same thing doesn't go for many US based companies.

What US law requires US companies above a certain minimal (~50 employees) size to "hire" government employees to supervise their operations at the innermost layers?

What US law makes all US corporate intellectual property and information legally owned by the government?

Google barely even complies with subpoenas.

mrex··on Rolling-PWN vulnerability affects all Honda vehicles
RSA SecureID has been doing this for decades and decades. They use a not-tremendously-accurate battery backed quartz RTC with some drift compensation built into the server side.

There are a ton of other options though. Atomic clock signals are broadcast nationwide in the US. GPS, Glonass, etc. signals broadcast the time. Cellular networks broadcast the time.

mrex··on Rolling-PWN vulnerability affects all Honda vehicles
Really, is TOTP too much to ask when they are charging $300-$500 for a single replacement key anyway?
← PreviousPage 3 of 3