Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

21–30 of 122 posts

Re: Tethered Jailbreaks Are Back

#21
post #14

Earlier quoted context omitted.

> You need physical access I don't understand why people keep downplaying this. The whole point of a secure phone is that the data can't be accessed even with physical access.

The attack where you implant some kind of backdoor to capture the data is possible even without this exploit, it just makes it easier.

How would such an attack (without this exploit) be pulled off?

Re: Tethered Jailbreaks Are Back

#22
post #21
post #14

Earlier quoted context omitted.

The attack where you implant some kind of backdoor to capture the data is possible even without this exploit, it just makes it easier.

How would such an attack (without this exploit) be pulled off?

For example, you could implant a hardware backdoor that monitors the touchscreen inputs

Re: Tethered Jailbreaks Are Back

#24
post #19

This will delight the one person in ten thousand who wants to jailbreak their own phone, and the border police in Australia (mandatory scans of phone required on demand), or China, or stalkerware retailers, or repair shops who like to rat around on customers' phones. Guess which will be the more common use?

Reboot your phone if you know you have given it to someone you don't trust.

Re: Tethered Jailbreaks Are Back

#25
post #10

Earlier quoted context omitted.

> if there's a real security risk There is, but it's not that great. You need physical access to the device and it won't be persistent (a reboot will clean it).

Anything electronic connected via the lightening port has physical access for example: a charger. A charger could be programmed to let a device in a low battery state to run the rest of the way down to empty to cause a reboot before starting to recharge. Not undetectable. But typical users would probably assume user error or a faulty charger before suspecting malware.

The exploit only works in DFU mode. The user would have to press a button chord in order to reboot into DFU for that to work, and it’s not easy to do accidentally

Re: Tethered Jailbreaks Are Back

#26
post #12
post #10

Earlier quoted context omitted.

> if there's a real security risk There is, but it's not that great. You need physical access to the device and it won't be persistent (a reboot will clean it).

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

Ha, I wonder if an attacker could use this bug to prevent or fake the rebooting process by changing the behavior of the lock/volume buttons when they’re held.

I know there’s also a “hard reset” you can do with volume up -> volume down -> power, not sure if that works at a lower level.

Re: Tethered Jailbreaks Are Back

#27
post #19

This will delight the one person in ten thousand who wants to jailbreak their own phone, and the border police in Australia (mandatory scans of phone required on demand), or China, or stalkerware retailers, or repair shops who like to rat around on customers' phones. Guess which will be the more common use?

Reboot your phone if you know you have given it to someone you don't trust.

This is a persistent compromise. That will not help.

Re: Tethered Jailbreaks Are Back

#28
post #26
post #12

Earlier quoted context omitted.

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

Ha, I wonder if an attacker could use this bug to prevent or fake the rebooting process by changing the behavior of the lock/volume buttons when they’re held. I know there’s also a “hard reset” you can do with volume up -> volume down -> power, not sure if that works at a lower level.

Seems likely that the hard reset works on a lower level as it works even if the phone is hung.

Re: Tethered Jailbreaks Are Back

#29

Interesting that the writers of this article are a company that sells a library to help developers detect their app running on jailbroken devices. https://blog.trailofbits.com/2017/10/12/ios-jailbreak-detect...

Trail of Bits sells a jailbreak detection app the same way Ikea sells Swedish Meatballs. It's good jailbreak detection, but it's hardly what Trail is about.

Re: Tethered Jailbreaks Are Back

#30
post #12
post #10

Earlier quoted context omitted.

> if there's a real security risk There is, but it's not that great. You need physical access to the device and it won't be persistent (a reboot will clean it).

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

I reboot my phone once in a blue moon, but my phone reboots itself roughly every other day (usually because I space on charging it). Am I that unusual, or is "the phone is rarely going to reboot" not really a reliable predicate for attackers?
Post reply on HN