Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

61–70 of 122 posts

Re: Tethered Jailbreaks Are Back

#61
post #30
post #12

Earlier quoted context omitted.

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

I reboot my phone once in a blue moon, but my phone reboots itself roughly every other day (usually because I space on charging it). Am I that unusual, or is "the phone is rarely going to reboot" not really a reliable predicate for attackers?

Anecdotal, but my family members reboot slightly less frequently than iOS updates come out (they miss a couple).

Re: Tethered Jailbreaks Are Back

#62
post #51

Earlier quoted context omitted.

Even in the case of an evil maid attack, a device that has been out of your sight and then demands that you enter the passcode instead of allowing you to use biometrics is immediately suspicious.

Uh - this is the standard on iOS - after a certain amount of time or reboot or the power button x5 shortcut, iOS will demand your passcode instead of TouchID/FaceID.

But if the phone has never left your area of trust during that time, there's no problem. If the phone has, then force a reboot of the thing before typing in your PIN. Say you have to walk into a place that demands you relinquish your personal device, but when it is returned to you it requests your pin. The suggestion here is that you reboot your phone to help ensure this jailbreak wasn't done to you. It seems like a simple thing, and fairly painless in this case. Just because you're paranoid doesn't mean...

Re: Tethered Jailbreaks Are Back

#63
post #53

Earlier quoted context omitted.

So far, only iOS can run on iDevices, which means if you want to use Apple hardware you have to use iOS.

I hardly see any compelling reason to stick to Apple hardware.

Well it appears Apple are really working towards user privacy as their main sell where android is locked in with Google Play services so though I do not personally have a preference I do know why some people choose Apple devices.

Re: Tethered Jailbreaks Are Back

#64

Honestly, if there's a real security risk, I'm surprised Apple hasn't recalled the phones or offered to repair them. Unpatchable firmware flaws are (or should be) no different from hardware flaws in this respect.

Apple isn’t really known for doing recalls until they absolutely have to

"Take the number of 'iPhones' in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one."

A modified version of the movie quote to fit the discussion

Re: Tethered Jailbreaks Are Back

#65
post #63

Earlier quoted context omitted.

I hardly see any compelling reason to stick to Apple hardware.

Well it appears Apple are really working towards user privacy as their main sell where android is locked in with Google Play services so though I do not personally have a preference I do know why some people choose Apple devices.

You can disable Google Play Services on a rooted Android. Besides I'm pretty sure all baseband CPUs have backdoors the carriers can tap into at any time.

Re: Tethered Jailbreaks Are Back

#66
Oh, here's a biz idea: build exploit into device, then when you've got something better/stronger/faster to sell, you leak the exploit and let the press urge people to buy your latest.

Re: Tethered Jailbreaks Are Back

#67
post #51

Earlier quoted context omitted.

Uh - this is the standard on iOS - after a certain amount of time or reboot or the power button x5 shortcut, iOS will demand your passcode instead of TouchID/FaceID.

But if the phone has never left your area of trust during that time, there's no problem. If the phone has, then force a reboot of the thing before typing in your PIN. Say you have to walk into a place that demands you relinquish your personal device, but when it is returned to you it requests your pin. The suggestion here is that you reboot your phone to help ensure this jailbreak wasn't done to you. It seems like a…

Good point - I always turn off my devices when entering a checkpoint/border.

Re: Tethered Jailbreaks Are Back

#68

Yay! I have fond memories of my friends (and eventually me, on the family iPad) jailbreaking our devices and doing stuff with them. A lot of the things I saw from jailbreaks were incorporated into later iOS updates- I'm curious (and excited!) to see what develops out of this wave.

What's the point now that we have Android?

Android appears to be about to lose the ability to run downloaded executables (see Termux), but this also has nothing to do with the discussion.

Re: Tethered Jailbreaks Are Back

#69
As I see it, the effect of this is twofold. While it's bad for (at least some of) the iDevice users who carry sensitive data - it might also be just the thing that makes those users buy a new device. I guess that would be a "good" security issue in Apple's book.

And no, I'm not implying that Apple has designed this security flaw in order to sell more devices.

Re: Tethered Jailbreaks Are Back

#70
post #63

Earlier quoted context omitted.

I hardly see any compelling reason to stick to Apple hardware.

Well it appears Apple are really working towards user privacy as their main sell where android is locked in with Google Play services so though I do not personally have a preference I do know why some people choose Apple devices.

Apple is marketing privacy while storing encryption keys in China and becoming a services business. The more their revenue shifts away from hardware the more they'll be compelled to collect data to improve their services. There's no way around this.
Post reply on HN