Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

41–50 of 122 posts

Re: Tethered Jailbreaks Are Back

#42
post #5

I jailbroke my old iPhones but that was in an earlier less featureful iOS era. I wonder what hackers will be able to provide such that I'd do it on an SE. Curious now as much as I am skeptical.

All I wanted is a mirrored CarPlay option with a cursor for people who use a joystick instead of a touchscreen. I know this exists in the jailbreaking community (minus the cursor).

Re: Tethered Jailbreaks Are Back

#43

Yay! I have fond memories of my friends (and eventually me, on the family iPad) jailbreaking our devices and doing stuff with them. A lot of the things I saw from jailbreaks were incorporated into later iOS updates- I'm curious (and excited!) to see what develops out of this wave.

What's the point now that we have Android?

GarageBand. iMovie. Both of which can have their projects opened in Logic Pro or Final Cut, an irreplaceable workflow for which there is no Android equivalent. Audio Bus. Not Google. For me, ARkit is huge for some hobby projects.

Re: Tethered Jailbreaks Are Back

#44

Yay! I have fond memories of my friends (and eventually me, on the family iPad) jailbreaking our devices and doing stuff with them. A lot of the things I saw from jailbreaks were incorporated into later iOS updates- I'm curious (and excited!) to see what develops out of this wave.

a proper firewall (not just safari content filtering or dns blocking) would be wonderful, one with a nice enough UI, like hands off or little snitch on mac.

there used to be firewall ip and protect my privacy on cydia, but both of those seem to no longer be maintained.

Re: Tethered Jailbreaks Are Back

#45
post #15
post #6

Earlier quoted context omitted.

>library to help developers detect their app running on jailbroken devices How does this work? I thought iOS apps are sandboxed to an extent where it shouldn't be possible to snoop around to determine which processes are running and such.

We discovered/developed a suite of side channels that let us indirectly read iOS system state from inside the sandbox. There are many different checks across unknown deviations, known jailbreak files and utilities, and runtime behaviors that help us narrow down whether your phone has been modified. It's not perfect, but it's the best you can do from within the Apple App sandbox.

If they used a language like Rust instead of Swift, iOS would be much more immune to these sorts of attack. There would be no side channels.

Re: Tethered Jailbreaks Are Back

#46
post #19

This will delight the one person in ten thousand who wants to jailbreak their own phone, and the border police in Australia (mandatory scans of phone required on demand), or China, or stalkerware retailers, or repair shops who like to rat around on customers' phones. Guess which will be the more common use?

You can already assume that states are sitting on exploits that they've found or bought, and that they can compel companies to provide some form of access via NSLs or secret courts.

Re: Tethered Jailbreaks Are Back

#47

Interesting that the writers of this article are a company that sells a library to help developers detect their app running on jailbroken devices. https://blog.trailofbits.com/2017/10/12/ios-jailbreak-detect...

Interesting that Apple forces you to use your device on their terms :)

Re: Tethered Jailbreaks Are Back

#48

Interesting that the writers of this article are a company that sells a library to help developers detect their app running on jailbroken devices. https://blog.trailofbits.com/2017/10/12/ios-jailbreak-detect...

Interesting that Apple forces you to use your device on their terms :)

since the release of ios 13 it has had multiple updates :)

Re: Tethered Jailbreaks Are Back

#49

Earlier quoted context omitted.

> You need physical access I don't understand why people keep downplaying this. The whole point of a secure phone is that the data can't be accessed even with physical access.

You need physical access AND the device pin. None of these hacks allow you to decrypt the device without the pin. The best you can do is load malware that would grab the pin when the user types it in so the defense for this is if the government ever takes your phone for inspection make sure to reboot it before typing in a pin.

Even in the case of an evil maid attack, a device that has been out of your sight and then demands that you enter the passcode instead of allowing you to use biometrics is immediately suspicious.

Re: Tethered Jailbreaks Are Back

#50
post #20

Earlier quoted context omitted.

Makes sense given how they try and spin this is only good for pirates (and researchers), because they would be the only ones who would like a jailbroken device.

A decade of corporate brainwashing has convinced people that only criminals want to control the device they own.

Most people don't own, they use payment plans
Post reply on HN