Live data from Hacker News

iMessage: Malformed Message Bricks iPhone

bugs.chromium.org

161–170 of 279 posts

Re: iMessage: Malformed Message Bricks iPhone

#161

Earlier quoted context omitted.

> What more functionality are people clamoring for? All those features in a market where lots of people you'd be chatting with are on Android, I'd suspect.

See samoa below, half of his friends using iphone disable imessage??? It's nonsensical. iMessage works wonderfully.

In the early days, iMessage had some availability issues - the only way you could get/send texts for a couple hours would be to switch it off so they'd send as SMS.

There was also a bug that allowed a malicious message to crash phones sometime last year where the recommended fix was turning off iMessage (similar to this one).

Some folks probably don't remember to turn it back on after these incidents.

Re: iMessage: Malformed Message Bricks iPhone

#162
post #75
post #68

Earlier quoted context omitted.

Security researchers have to assume that if they've found a vulnerability, it's only a matter of time before the evil people will find it as well - that is if they haven't found it already. That's why all disclosures come with window - if they don't, the companies aren't under any pressure to update their systems, the exploit start being used in the wild, etc. The window is not ideal, but it is better than no window.…

Still make no sense, I agree the window is a good policy to force lazy vendors to act as they should. But what’s the point of reducing the window for nice vendors who quickly delivered a patch? This is totally counter productive. In order to incentivize vendors to deliver patches more and more quickly, good actors should profits from that extra time to secure their user base. In a ideal world that might even permit t…

Your incentive line in no way matches reality. In the past every vendor that is given an unlimited open timeline on patching has not. This includes Microsoft, Apple, Oracle and most of the other large vendors. Most of them are better at patching, but this is mostly because of the risk at of someone zero daying the patch and destroying the userbase.

Security is not an ideal world, in fact I would say it is the opposite.

Re: iMessage: Malformed Message Bricks iPhone

#163

I see a free data hack: Load a version of iMessage that never acknowledges the message, but saves the data (and doesn't brick the phone). Send lots of data, acknowledge via other means (checksum sent over email etc). How much data could be sent this way? GBs?

It doesn’t work that way. The person with a cell bill will still be charged the downloaded data.

Re: iMessage: Malformed Message Bricks iPhone

#164

Earlier quoted context omitted.

second that. half of my friends using iphones dont enable imessage. thus penetration (in my circles) is way too low to make it useful.

Considering it's enabled by default, i'm really curious why you would want to do that.

It costs money to activate it (or so says the pop up that appears when you set up an iPhone).

Also if I switch to Android I don’t have to worry about disabling iMessage before. (Not that anybody in my country would ever send an iMessage or an SMS though...)

Re: iMessage: Malformed Message Bricks iPhone

#165
post #138

Earlier quoted context omitted.

Fascinating problem. Since I have Faraday cages on the mind today (not that I know much more than ~10 minutes of reading)... simply isolating the phone from all signals would block both the message and any software update, so that doesn't work. But what if you attached it to wifi but not to the cell network? Either have the wifi router (itself having a wired connection) and the phone in the same shield; or, I guess,…

To answer your question about selectively blocking, just put the wifi router inside the cage. To the point though, feature phones didn't have WiFi generally. I'm also not sure how doing so would fix the issue, unless you could block the number perhaps.

Feature phones also didn't have OTA updates. I remember taking my phones to service centers to get the latest software flashed. Later on you could flash it yourself with a cable to your PC, browsing esato.com for new versions.

Re: iMessage: Malformed Message Bricks iPhone

#166
post #104

Earlier quoted context omitted.

Where I live nobody uses iMessage so this sounds like a good workaround :P (Yes yes I know it’s been patched already...)

I never understood this, why would anyone want to deal with ANOTHER app to do messaging? iMessage is built in, integrated, and has end to end encryption. What more functionality are people clamoring for?

People want to use one app to do all their messaging. iMessage is not that app unless 100% of the people you message use iPhones. For a lot of people Whatsapp or Telegram can be that app.

Re: iMessage: Malformed Message Bricks iPhone

#167

Earlier quoted context omitted.

No, never iOS is deisgned by Gods themselves. https://www.theiphonewiki.com/wiki/Malware_for_iOS

Not all malware is a "virus." Has iOS ever had anything where one app could "corrupt" other apps?

> Not all malware is a "virus."

Haha, this is called moving the goal post. Fanboys do this all the time :)

Edit: Plenty of buffer overflow and momory corruptions are listed for iOS just in 2019.

https://www.cvedetails.com/vulnerability-list.php?vendor_id=...

Re: iMessage: Malformed Message Bricks iPhone

#168

I see a free data hack: Load a version of iMessage that never acknowledges the message, but saves the data (and doesn't brick the phone). Send lots of data, acknowledge via other means (checksum sent over email etc). How much data could be sent this way? GBs?

This doesn't work with iMessage, because the carrier sees iMessage no differently from any other kind of data download. However, a friend of mine tried doing something similar using the @txt.att.net (or equivalent for your carrier) email-to-SMS trick and wrote an Android app that parsed the messages. They promptly received a firmly worded email from AT&T and were forced to abandon the project.

Re: iMessage: Malformed Message Bricks iPhone

#170
post #136

Earlier quoted context omitted.

Back in the day AOL parsed HTML for it's instant messages, a would blue screen any client running windows. It was quite easy to empty chat room(s) using this.

Hahaha on Yahoo we called it booting.

On AOL we called it "punting", and the apps that facilitated it were the first reason I ever wanted to code.
Post reply on HN