Earlier quoted context omitted.
Filter. Spam detection wasn’t exactly a novel idea back then either.
With what? Especially back then, I wouldn’t assume there is anything with a programmable CPU in the data path that can inspect and filter things at line rate.
iMessage: Malformed Message Bricks iPhone
271–279 of 279 posts
Re: iMessage: Malformed Message Bricks iPhone
#272Earlier quoted context omitted.
buffer overflow and memory corruption is not a virus. He asked a specific question, and people answered different questions while ignoring the question he actually asked.
His specific question is just a diversion tactics. Parent comment was about Apple intentionally misleading gullible people for many years by claiming that MACs don't get virus. They didn't change until high profile attacks hit and it was no longer viable to make the claim. Instead of commenting on this, he just moved the goal post to iOS never getting a Virus. What does iOS never getting a Virus has anything to do wi…
His specific question has an answer, and you chose to obfuscate instead of answering.
Re: iMessage: Malformed Message Bricks iPhone
#273Earlier quoted context omitted.
Security researchers have to assume that if they've found a vulnerability, it's only a matter of time before the evil people will find it as well - that is if they haven't found it already. That's why all disclosures come with window - if they don't, the companies aren't under any pressure to update their systems, the exploit start being used in the wild, etc. The window is not ideal, but it is better than no window.…
Microsoft (employees) has repeatedly argued that 90d can be unreasonable for Windows due to the development and testing cycle, which also has to align with “patch Tuesday”. I haven’t heard the complaints recently so maybe they’ve streamlined part of the process.
Re: iMessage: Malformed Message Bricks iPhone
#274Earlier quoted context omitted.
Hahaha on Yahoo we called it booting.
Easier way to boot a group of people off of Yahoo Games back in the day when you wanted to clear up a room... Just post in the general chat area. “Hey, to speed up Yahoo Games, press alt-f4.”
Re: iMessage: Malformed Message Bricks iPhone
#275Speaking as an ex-Apple employee, I'll just point out that a really malicious actor could have used this to harm some significant percentage of the installed iOS infrastructure, and done critical damage to Apple as a company with it. In fact, I don't know the percentage of users still on <12.3, but maybe they still could. A band-aid fix for this one bug should not be where they stop here.
> A band-aid fix for this one bug should not be where they stop here. What do you suggest they do?
Architecture-wise some thought should be given to keeping iOS from being DoS'd by the crash/respawn of any service.
Also, looking at the "assuming it's a string" line from the problem description, Apple needs to make an investment look through the codebase for this same error in other guises.
That's what occurs to me off the top of my head anyway.
Re: iMessage: Malformed Message Bricks iPhone
#276I see a free data hack: Load a version of iMessage that never acknowledges the message, but saves the data (and doesn't brick the phone). Send lots of data, acknowledge via other means (checksum sent over email etc). How much data could be sent this way? GBs?
This doesn't work with iMessage, because the carrier sees iMessage no differently from any other kind of data download. However, a friend of mine tried doing something similar using the @txt.att.net (or equivalent for your carrier) email-to-SMS trick and wrote an Android app that parsed the messages. They promptly received a firmly worded email from AT&T and were forced to abandon the project.
Why did your friend choose to send data over SMS? Why was AT&T upset at his project?
Re: iMessage: Malformed Message Bricks iPhone
#277Earlier quoted context omitted.
buffer overflow and memory corruption is not a virus. He asked a specific question, and people answered different questions while ignoring the question he actually asked.
His specific question is just a diversion tactics. Parent comment was about Apple intentionally misleading gullible people for many years by claiming that MACs don't get virus. They didn't change until high profile attacks hit and it was no longer viable to make the claim. Instead of commenting on this, he just moved the goal post to iOS never getting a Virus. What does iOS never getting a Virus has anything to do wi…
You then went on to ignore that contradiction. Does that fall under "moving the goal post" too?
I also suspect you created a new account for the sole purpose of supporting yourself in this argument. [1]
Re: iMessage: Malformed Message Bricks iPhone
#278Earlier quoted context omitted.
They're (Apple) rather lucky that their user base vehemently upgrades whenever possible.
I've iPhone user I've ever met outside tech circles avoids installing OS updates. They end up updating soon anyway for a variety of reasons (some updated apps stop working, update occurs "on its own" overnight, to get rid of of the notification icon, and so on).
Re: iMessage: Malformed Message Bricks iPhone
#279Earlier quoted context omitted.
/ping +++ATH0
There's supposed to be a delay in the Hayes protocol to prevent this kind of thing, but many "Hayes compatible" implementations didn't implement that part (through ignorance? working around a patent?), so this trick would work pretty well . . .
Hayes themselves would even insert the sequence in press releases posted to Usenet. https://groups.google.com/forum/#!topic/comp.dcom.modems/Vr2...