Live data from Hacker News

Exploiting the Wi-Fi Stack on Apple Devices

googleprojectzero.blogspot.com

1–10 of 85 posts

Re: Exploiting the Wi-Fi Stack on Apple Devices

#3
I'd love to know how many hours were needed to develop this exploit from start to finish, and how many dead ends the researcher ran into along the way.

Just writing the blog post and generating all the images for it must've taken many days.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#5

Wonder if something like this was used to get into the San Bernardino shooter's phone by the FBI

The shooter had an iPhone 5C[1], which according to the article uses USB, so the DMA PCIe exploit detailed here wouldn't work for it.

Not saying it wasn't something similar, but it could have been pretty different.

1. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Re: Exploiting the Wi-Fi Stack on Apple Devices

#6
post #3

I'd love to know how many hours were needed to develop this exploit from start to finish, and how many dead ends the researcher ran into along the way. Just writing the blog post and generating all the images for it must've taken many days.

From the project-zero bug (https://bugs.chromium.org/p/project-zero/issues/detail?id=13...), it looks like the first discussion on the issue dates back to July 3, with a working exploit posted just yesterday.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#9

Wonder if something like this was used to get into the San Bernardino shooter's phone by the FBI

The shooter had an iPhone 5C[1], which according to the article uses USB, so the DMA PCIe exploit detailed here wouldn't work for it. Not saying it wasn't something similar, but it could have been pretty different. 1. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

It has a Lightning port, so maybe a different at-the-time undisclosed DMA exploit?

Re: Exploiting the Wi-Fi Stack on Apple Devices

#10

Amazing. Did they need to jailbreak or physically open the phone to find all this stuff? They talk about reversing binary images and using their "Legilimency" toolkit; I wonder if a vanilla phone was enough to research all this and propagate through Wi-Fi.

I'm guessing there must be other jailbreaks involved to be able to observe and experiment on the ios kernel side of things while developing the wifi chip exploit; going in all blind from the wifi side only sounds impossible. The question now is, are they sitting on 0day jailbreaks for current iOS versions or did they have to do all the tests on legacy iOS versions?
Post reply on HN