Live data from Hacker News

Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

motherboard.vice.com

1–10 of 49 posts

Re: Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

#2
Is there any info on how GrayKey worked? My understanding is that in recent models the SEP was supposed to prevent that kind of brute forcing of passcodes at the hardware level — and also enforce a secure boot chain that prevents loading hostile firmware (which it looks like GrayKey did based on screen shots). This would seem to involve an exploit of the SEP which is very serious... or was there some simpler exploit?

Anyone?

Re: Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

#6
>In 2017, however, Solnik was hired by Apple to work on its security team, specifically on the so-called red team, which audits and hacks the company’s products. His talk at Black Hat had apparently impressed the folks at Cupertino. A few weeks later, however, he abruptly left the company, according to multiple sources.

>The full story of Solnik’s short stint at Apple is a closely-guarded secret. Motherboard spoke to dozens of people and was unable to confirm the specifics around his leaving the company; one source within Apple told me information about Solnik is “incredibly restricted,” and another confirmed that even within Apple, few know exactly what happened.

Why hire someone that was previously selling "offensive security tools and exploits to governments" into a sensitive role like that? It's incredibly naive to think that just because you're employing them now that they are actually loyal to you. Surely the insider threat is greater than any expertise that person has. Just pay them a bug bounty for specific information and keep them at arms length. Finding high integrity security researchers to hire is more important than raw talent.

Re: Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

#8
post #7

> “They are stolen from the factory and development campus,” a person who sells these devices on Twitter told Motherboard. Haha yeah that and employees' homes and cars being burglarized.

Sometimes it's just Apple employees leaving them at a bar and journalists holding them for ransom.

Re: Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

#9
post #7

> “They are stolen from the factory and development campus,” a person who sells these devices on Twitter told Motherboard. Haha yeah that and employees' homes and cars being burglarized.

Which makes me wonder why even go with one story over the other. They both contain theft, so if you accept that there was theft, then it's illegal to buy them, and illegal for them to sell them knowing that. I guess maybe it's so they look less like a common criminal and more like a white-collar criminal that only steals from super rich companies?

Re: Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

#10
There are some issues with the article:

> I used one of these devices and obtained “root” access on it, giving me almost total control over the phone; gaining root access allows researchers to probe many of the phone’s most important processes and components.

Root access does not give total control on iOS. There are many other things that stand in the way of "full access".

> “Switchboard devices” are another term for some dev-fused phones, which refers to the proprietary operating system they run.

No. Development-fused devices can run iOS; "Switchboard devices" are devices that have not had iOS flashed on them and are still running Switchboard.

Post reply on HN