Live data from Hacker News

Exploiting the Wi-Fi Stack on Apple Devices

googleprojectzero.blogspot.com

71–80 of 85 posts

Re: Exploiting the Wi-Fi Stack on Apple Devices

#71
post #67
post #57

Earlier quoted context omitted.

In 5 years we're gonna wonder how we got to the point where you can't easily turn off wifi, slowly dumbing down devices for all of us for the sake of your project manager and the like.

@mikeash it takes a minimum of 4 or 5 taps and button presses.

On my 6+, the sequence is: press home button, tap Settings, Wi-Fi, Off. That's 3-4 depending on whether you count the home button.

On a 6s or newer, with 3D touch, you can cut it down to 2-3: unlock, force touch on Settings and toggle WiFi from the menu that appears. (That might be 1-2, I forget whether you can force touch and drag to what you want to activate, or whether it has to be a separate tap.)

Re: Exploiting the Wi-Fi Stack on Apple Devices

#72
post #62

Earlier quoted context omitted.

There's also a relatively low attack value and attack surface for encrypted Android phones vs encrypted iPhones. Everyone who runs an iPhone has it encrypted, while relatively few people running Android devices have them encrypted. In terms of attack surface, the SecureEnclave has many APIs, some of which have had vulnerabilities in the past and it's quite possible to envision a scenario in which others were found an…

Also encryption by default and much larger user base mean there is more focus on iOS than Android (like the old windows versus mac virus argument) the difference I see is that you are much more likely to get compromised by an application on Android than iOS. And since Google has been very friendly with the USG I would find it much more likely that Enclave or not that it will be NSA weakened crypto that will be the de…

> weakened crypto that will be the demise of your Android rather than exotic exploits of your wifi.

I don't think there's any truth to this - if the crypto were weakened you'd see it broken by that quite quickly - but it's quite strong and follows well accepted stands in the cryptography community, have a look yourself if you like. It's using dm-crypt and dm-crypt is fairly heavily tested and reviewed. Debian and likely Purism use the exact same, so certainly wouldn't be any better in that way.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#73
post #21

Earlier quoted context omitted.

If you want to avoid cellular charges, shouldn't you be turning off cellular?

The problematic scenario goes like this: 1. You're in a coffee shop. The WiFi sucks today. You turn off WiFi so you can use your cellular connection instead. 2. Many hours later, you go home, having forgotten about #1. 3. You binge-watch the entirety of Doctor Who streaming on your phone, not realizing the phone is still using cellular. 4. Large bill from your provider.

Didn't iOS 10 or whichever add cellular assist to WiFi? I know some people raged about it, but I find it useful for the scenario you just mentioned.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#74
post #21

Earlier quoted context omitted.

The problematic scenario goes like this: 1. You're in a coffee shop. The WiFi sucks today. You turn off WiFi so you can use your cellular connection instead. 2. Many hours later, you go home, having forgotten about #1. 3. You binge-watch the entirety of Doctor Who streaming on your phone, not realizing the phone is still using cellular. 4. Large bill from your provider.

Didn't iOS 10 or whichever add cellular assist to WiFi? I know some people raged about it, but I find it useful for the scenario you just mentioned.

It did, but I'm not sure how well it really works. In my own experience, I still see lots of networking failures if I'm far enough from my house for the network to be dodgy but not so far that it disconnects, or if I connect to crappy public WiFi.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#75
post #68

Earlier quoted context omitted.

5. Realize you should have gotten a subscription with an adequate data plan. 6. Get said subscription. 7. Stop worrying.

Most people don't live in countries such as Kuwait where it is normal (and affordable) to watch 4k netflix streams via LTE.

Kuwait? I live in northern Europe, and I have 45GB on my perfectly ordinary ~$27 plan.

Re: Exploiting the Wi-Fi Stack on Apple Devices

#76
post #66
post #55

Earlier quoted context omitted.

> Apparently Android-encrypted phones are the safest though. That's odd. I guess the implication is that iPhone hsm is broken (or they can get past a short pin via an exploit that allows brute forcing - typically an hsm should (be possible to configure to) permanently destroy the keys after N attempts). I suppose it demonstrates that secure encryption requires the user to memorise something equivalent of 96-128 bits…

Your intuition is correct on that. The iPhone encryption from San Bernardino had a 4-digit pin + a long salt, and the long salt is in the iPhones secure enclave. However, the phone would erase itself (don't know if it's the salt or erase everything) after 10 tries. If they were able to image the phone and get the long salt, the keyspace is only 10000, which is trivla to do on a cheap computer today. I believe you can…

As far as I remember, they were able to do copies of the iPhone. (I guess, similar to a nandroid backup on android devices. Explicitely asked if that needs root, and he said they don't need root or any modified bootloader stuff at all.)

They also had jailbreaks/exploits for 10.2 (or the latest version at ~2 months ago)

Re: Exploiting the Wi-Fi Stack on Apple Devices

#77
post #3

I'd love to know how many hours were needed to develop this exploit from start to finish, and how many dead ends the researcher ran into along the way. Just writing the blog post and generating all the images for it must've taken many days.

I have followed iOS JB for years and keep up with exploit dev and mitigation/defense. The usage of source code and avoiding deep assembly documenting helped a lot. You are still looking at several man days of deep work on understanding the driver and stack. KASLR was the only real mitigation to bypass. That could have been a difficult part worth it's own discussion. Bypassing ASLR typically requires an info leak. I t…

Is the source for this code only Apple's open-source publishings?

Re: Exploiting the Wi-Fi Stack on Apple Devices

#78

What is the story with Project Zero? What is the strategy here? If you think about it, pointing out flaws in competitors' products is actually unusual for businesses, especially large ones. It raises questions of motives, of trust (are they drumming up business in a negative way? Can I trust what company X says about their chief rival? Are they exaggerating or spinning it?), and it looks unsavory: You don't win in th…

I submit for your consideration that: 1. The Google Project Zero guys are idealists and motivated by increasing security. 2. Google security is taken far more seriously than most other companies 3. If Apple and Google competed in publicizing exploits, Google would win [is winning].

If everyone competed in publicizing exploits and like project zero coordinates disclosure with vendors, then _consumers_ win!

Re: Exploiting the Wi-Fi Stack on Apple Devices

#80

Why did Apple make it harder to turn off the WiFi radio in iOS11?

I think it’s safe to assume that most people turn off wifi when there is a wifi network that sucks and they want to switch to cellular. This is by far the most common reason, and it’s also what they think they accomplished. What they instead achieved up to iOS 10 was: * worse location data in maps * airdrop does not work * AirPlay might not work (doesn’t work across networks) * Handoff doesn’t work * phone call and s…

my main sorrow with the clearly misleading wifi-switch is to fall prey to those nasty mac-adress tracker in shops.

the other reasons you list are minor issues, who needs constant update possibilities, phone call forwarding to your Mac, airplay and handoff on the way? yes, I also forgot switch off wifi and burned through my volume, but we shouldn’t dumb systems down. People need to understand cause and effect, especially in IT.

Post reply on HN