Live data from Hacker News

iMessage: Malformed Message Bricks iPhone

bugs.chromium.org

91–100 of 279 posts

Re: iMessage: Malformed Message Bricks iPhone

#91
post #67

Earlier quoted context omitted.

The reasoning is that once a fix is out, by making it public then users can know about it and intentionally update their devices if they haven't yet.

The other side is that the moment a patch is released, people will diff it to the previous version making it much more likely this issue is found by a lot of independent people who might seek to exploit it.

The patch was released months ago

Re: iMessage: Malformed Message Bricks iPhone

#92
post #88

Earlier quoted context omitted.

The reasoning is that once a fix is out, by making it public then users can know about it and intentionally update their devices if they haven't yet.

That sounds like a logic flaw because iPhones and most other devices like it will normally auto update after a short while. I think more people will rely on that feature than browse, uh, bugs.chromium.org... This view of it will assist hackers in getting a head start before the auto update cycle gets to your device and you're notified. And if you're hit but something like this before that, your iPhone will no longer…

It was patched in march.

Re: iMessage: Malformed Message Bricks iPhone

#93

Since a restore works it cannot be called a brick though?

I agree with you. The title is misleading. I thought this was about frying the device. When people say the raspberry pi is design not to be bricked, they are referring to not fucking the circuitry beyond use without physical repair, not some user process stuck in an infinite loop.

Re: iMessage: Malformed Message Bricks iPhone

#94

Can this be avoided by disabling iMessage notifications? > The calling method then calls -[IMBalloonPluginDataSource _replaceHandleWithContactNameInString:] which calls im_handleIdentifiers on the 'NSString' which is really an NSNumber, which throws an exception as the selector does not exist in that class. Looks like they need to move more of their stuff to Swift to reduce snarfles like this. Stories like these (thi…

> Still, it's not so bad as the Windows XP-7 epoch, when eldritch nightmares walked the land. You are speaking like an Apple fanboy. Days of XP are in the past and even Windows 7/Windows 2008 fairs better than Apple OSX and iOS. This is especially bad as apple sells a false sense of security when they fail to build even the basics correctly. Their walled garden is paved with expensive ibricks. Edit: Those who think I…

Even now, I don't think any of macOS's recent failings are as bad as the Windows 10 update that deleted user documents [0], or all the official spyware and adware in the only operating system where you have to pay to even customize your wallpaper.

As for mobile, does anybody remember hearing of any iOS cross-app malware ("viruses") in the decade since it launched? I think that's pretty amazing.

[0] https://www.google.com/search?q=windows+update+deleted+docum...

Re: iMessage: Malformed Message Bricks iPhone

#95
post #89

Earlier quoted context omitted.

> Edit: Those who think I am speaking rubbish can refer this link. https://www.cvedetails.com/top-50-products.php That listing groups together all OS X bugs back to 2002 under one heading, but splits up each Windows version into its own entity. So the numbers aren't really comparable.

But the bottom of that page has a cumulative count by vendor which shows Apple having the second most security issues, only topped by Microsoft. Considering the fact that Microsoft has much bigger market share and therefore security research attention, that's quite an achievement.

You mean MS historically has 100% more security issues. Also IE alone competes with entire OSes in that top 10.

That proves the other comment right, but surely you can spin it other ways. Anyone who has switched from old windows to Mac doesn’t need numbers to tell how wild it was.

Re: iMessage: Malformed Message Bricks iPhone

#96
post #75
post #68

Earlier quoted context omitted.

Security researchers have to assume that if they've found a vulnerability, it's only a matter of time before the evil people will find it as well - that is if they haven't found it already. That's why all disclosures come with window - if they don't, the companies aren't under any pressure to update their systems, the exploit start being used in the wild, etc. The window is not ideal, but it is better than no window.…

Still make no sense, I agree the window is a good policy to force lazy vendors to act as they should. But what’s the point of reducing the window for nice vendors who quickly delivered a patch? This is totally counter productive. In order to incentivize vendors to deliver patches more and more quickly, good actors should profits from that extra time to secure their user base. In a ideal world that might even permit t…

I think patching is firmly in your hands now, and this data may help you choose to upgrade if you were holding off for some reason. Imagine your favorite iOS game was broken by the release that fixes this, so you've been ignoring the update. Now that you know your phone can be bricked by a malicious text message, you may decide "I guess I won't be playing that game for a while" and upgrade. The point is, pretty much everyone that applies every update (which is automatic) has the update now. The last few stragglers are probably waiting for information exactly like this. Now they have it.

Re: iMessage: Malformed Message Bricks iPhone

#97
post #89

Earlier quoted context omitted.

> Edit: Those who think I am speaking rubbish can refer this link. https://www.cvedetails.com/top-50-products.php That listing groups together all OS X bugs back to 2002 under one heading, but splits up each Windows version into its own entity. So the numbers aren't really comparable.

But the bottom of that page has a cumulative count by vendor which shows Apple having the second most security issues, only topped by Microsoft. Considering the fact that Microsoft has much bigger market share and therefore security research attention, that's quite an achievement.

I'm not going to comment on Apple's software security standards (and Microsoft deserves more kudos for their focus on security after the bad old days of XP), I'm just pointing out that summing up CVEs is not a valid way to compare.

> Considering the fact that Microsoft has much bigger market share and therefore security research attention

The OS X bug numbers also include a bunch of bugs for open source projects that are bundled with OS X (Perl, Ruby, Python, SQLite, PHP etc) which increases the security research attention.

Re: iMessage: Malformed Message Bricks iPhone

#98
post #89

Earlier quoted context omitted.

But the bottom of that page has a cumulative count by vendor which shows Apple having the second most security issues, only topped by Microsoft. Considering the fact that Microsoft has much bigger market share and therefore security research attention, that's quite an achievement.

You mean MS historically has 100% more security issues. Also IE alone competes with entire OSes in that top 10. That proves the other comment right, but surely you can spin it other ways. Anyone who has switched from old windows to Mac doesn’t need numbers to tell how wild it was.

> You mean MS historically has 100% more security issues.

For an OS used 1000% as often[0], yes.

I have no skin in this game, BTW, as I use neither. But given the number of security issues Apple has, I really bothers me that they still sell those products as somehow more secure.

[0] = https://en.wikipedia.org/wiki/Usage_share_of_operating_syste...

Re: iMessage: Malformed Message Bricks iPhone

#99
post #7

This is fixed in iOS 12.3 [1] and macOS 10.14.5 [2], both released on May 13th. As Natalie noted on the ticket, turning off iMessage will also prevent the bug. [1]: https://support.apple.com/en-us/HT210118 [2]: https://support.apple.com/en-us/HT210119

Do you know why is the upstream bug in "New (Open)" state, if it's fixed in currently released versions of iOS/macOS?

Maybe it still has to be fixed in the betas?

Re: iMessage: Malformed Message Bricks iPhone

#100
post #34

This brings back old memories from hardening the sms/text parsers of feature phones of yesteryear. There it wasn’t entirely uncommon that when you sent a malformed sms-deliver PDU (e.g. text message) to the phone and crashed parser that tried to decode it, it took also the phone down before it could ack the message back to SMSC. Which of course meant that as soon as phone was turned on and it registered to network, t…

There was a nice talk about this a few years ago at the CCC congress.

https://media.ccc.de/v/27c3-4060-en-attacking_mobile_phones

http://www.ngolde.de/sms/smsodeath_mulliner_golde_cansecwest...

Post reply on HN