Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

161–170 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#161
post #110

Earlier quoted context omitted.

This sound horrifying. If I use a hacked/modified FaceTime client, does this mean I'll be able to hear and see the other end before they pick up, even after the fix?

Facetime calls are end to end encrypted so I doubt a modified client would work.

Yeah, if you have a hacked iMessage client you probably could retire from bug bounties. At any rate the bug in question would pale in comparison to a rogue iMessage client.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#162

Earlier quoted context omitted.

Your specific claim was that Apple has "zero secure coding training, zero push for security reviews, zero push for security QA, zero accountability"–this isn't true at all. Sure, Apple's software has had some serious bugs in it, but this does not mean that they have no security practices in place.

I am not speaking about dedicated security teams. What security training is there for end-user app developers at Apple? From discussions with developers I know, it doesn't seem to exist, or at least not spread everywhere.

Maybe it's not enough for your satisfaction, but there are resources available for writing safe and secure code (I'm not sure if this is required, though), as well as regular audits by the security team.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#163
post #16
post #12

Security and privacy are two big parts of the marketing for the iPhone. I'm curious how they can mitigate the reputational damage. Edit: It gets worse: https://www.theverge.com/2019/1/28/18201383/apple-facetime-b... If the recipient rejects the call by pressing the power button, it starts sending video.

Why would this be any more reputationally damaging than the numerous other bugs with iPhone behavior? It’s not like iPhones have a reputation for not having bugs; it seems like every version has a passcode bypass or a DoS-via-iMessage. By some standards, this is worse (remotely triggerable, leaks audio/video), but in other cases it’s not as bad: the attacker’s Apple ID ends up in the call logs of the affected person.…

Well this is the top Twitter trend right now, for starters. It's a very visible, very easy to reproduce bug in a very popular service, and it's definitely going to hurt their reputation with consumers more than if it was something more technical yet equally or more dangerous.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#164
post #21

While they're getting a fix ready, might be smart to just disable FaceTime if you don't rely on it. https://www.imore.com/how-to-turn-on-off-restrict-facetime-i...

That just seems like a good idea anyways. FaceTime as a product just flat out seems stupid.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#165

Earlier quoted context omitted.

Facetime calls are end to end encrypted so I doubt a modified client would work.

If FaceTime is implemented the way the parent comment mentions (which it very well may not) I don't see why you could make a client that performs a proper key exchange to set up an end-to-end call and simply pretend grab the video instead of hiding it behind the "dailing" screen?

"The initial FaceTime connection is made through Apple server infrastructure that relays data packets between the users’ registered devices. Using APNs notifications and Session Traversal Utilities for NAT (STUN) messages over the relayed connection, the devices verify their identity certificates and establish a shared secret for each session. The shared secret is used to derive session keys for media channels streamed via the Secure Real-time Transport Protocol (SRTP). SRTP packets are encrypted using AES-256 in Counter Mode and HMAC-SHA1. Subsequent to the initial connection and security setup, FaceTime uses STUN and Internet Connectivity Establishment (ICE) to establish a peer-to-peer connection between devices, if possible."

Source: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#166

Just thinking out loud here - why isn't there legislation that makes it mandatory for phone manufacturers to send out a notification to all devices affected by serious security flaws (like this one)? Not only will fixing and rolling out an update take a while, there is also no guarantee that the update will be installed. Meanwhile, hackers will have a field day. Or maybe there is already one, and I'm blissfully ignor…

Just to play devil's advocate (not a lawyer though):

What constitutes a "phone"? Any device with cellular capabilities? What about WiFi calls? What if it's an industrial device with no network (LTE/data) access? Is a laptop with a 3G modem covered under this?

I would suspect the problem is in defining what devices to target, and also the fact that forcing any company to modify the functionality could be perceived as a slippery slope (i.e. security notifications first, NSA backdoors later...)

In Apple's defense, it is pretty difficult to miss an update alert considering it comes through as (a) a push notification, (b) a mandatory alert, and (c) a persistent red badge on the Settings app.

I agree that it might be a good idea to differentiate between a normal update and a security critical one, though.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#168

Earlier quoted context omitted.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

I remember some people discovered that you could kill the xscreensaver lock screen on Debian with Alt+SysRq+F some years back. Well, a decade back actually — 2009. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=562884

A fee years ago, I discovered that if someone was running dual monitors and using XScreenlock, you could unplug one of the monitors and it would bypass the lock screen. I have no idea if this is still possible, I've not used XScreenlock since then.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#169
post #137

Earlier quoted context omitted.

iPhones already have a "mute" slider switch. When I first looked into iPhones (after years of Androids), my instant reaction upon seeing the slider switch was "Ah! FINALLY! I can feel at peace in the knowledge that software vulnerabilities are powerless to hack my camera or microphone!" Of course, stupidly, the slider doesn't "mute" my camera or microphone, but only my speaker. For Apple to modify this slider so that…

Are you suggesting that the silent switch also turns off the camera and microphone?

Yup. Or, at the least, have a separate switch that does so.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#170

Earlier quoted context omitted.

Let's not forget https://www.cvedetails.com/cve/CVE-2013-1050/ and https://www.cvedetails.com/cve/CVE-2015-7496/ and https://www.cvedetails.com/cve/CVE-2017-8900/ (to a lesser extent). Check out https://www.cvedetails.com/vulnerability-list.php?vendor_id=... for more fun.

http://i.imgur.com/rG0p0b2.gif

Oh dear, I remember something similar was possible on iOS lockscreen multiple times. What version of Windows was that?
Post reply on HN