I'm not opposed to jailbreaking to check.
A deep dive into iOS Exploit chains found in the wild
101–110 of 202 posts
Re: A deep dive into iOS Exploit chains found in the wild
#102Earlier quoted context omitted.
> The most obvious suspect is China: they have gulag camps in Xinjiang where Uygurs are interned, up to 1.1 million according to the UN[^2]. The dominant ethnic in China is Han, and Uygurs have been oppressed for decades. But China doesn't need exploits to spy on their iPhone-using citizens, right? Because Apple has been cooperating with the Chinese government.
Do you have some evidence of that? Aside from iCloud hosting and App Store censorship, I haven’t heard of a case where they’ve weakened security for the Chinese government.
Re: A deep dive into iOS Exploit chains found in the wild
#103Any way to check if my iPhone is affected? I'm still on 12.1.2, which was released before the fix, so if I'm affected, I should still have the malware on my device. I'm not opposed to jailbreaking to check.
Re: A deep dive into iOS Exploit chains found in the wild
#104Any way to check if my iPhone is affected? I'm still on 12.1.2, which was released before the fix, so if I'm affected, I should still have the malware on my device. I'm not opposed to jailbreaking to check.
1. https://googleprojectzero.blogspot.com/2019/08/implant-teard...
Re: A deep dive into iOS Exploit chains found in the wild
#105Any way to check if my iPhone is affected? I'm still on 12.1.2, which was released before the fix, so if I'm affected, I should still have the malware on my device. I'm not opposed to jailbreaking to check.
Re: A deep dive into iOS Exploit chains found in the wild
#106Earlier quoted context omitted.
What’s the relation to the first link though? That looks like an old twitter thread.
Did you look at the screenshot and read the translation? Appears to be a real-time tracking database of Uighurs...
Re: A deep dive into iOS Exploit chains found in the wild
#107Earlier quoted context omitted.
Do you have some evidence of that? Aside from iCloud hosting and App Store censorship, I haven’t heard of a case where they’ve weakened security for the Chinese government.
"Aside from iCloud hosting" is a pretty big "aside"
Re: A deep dive into iOS Exploit chains found in the wild
#108I wonder what happens when Apple distribute the update and it detects this is on your phone. Do they even notify you?
Re: A deep dive into iOS Exploit chains found in the wild
#109Re: A deep dive into iOS Exploit chains found in the wild
#110Earlier quoted context omitted.
> 2FA makes it profoundly more difficult to compromise an account. Just because the attacks are dumb. If your computer is pwned, it should wait for you to 2FA, and then when you "log out"-- don't, do malicious stuff instead.
That's why 2FA should be performed at transaction confirmation time for sensitive operations, not just at login or periodically.