Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

91–100 of 122 posts

Re: Tethered Jailbreaks Are Back

#91

Yay! I have fond memories of my friends (and eventually me, on the family iPad) jailbreaking our devices and doing stuff with them. A lot of the things I saw from jailbreaks were incorporated into later iOS updates- I'm curious (and excited!) to see what develops out of this wave.

What's the point now that we have Android?

iOS doesn't sent your every click to Google?

https://digitalcontentnext.org/wp-content/uploads/2018/08/DC...

Re: Tethered Jailbreaks Are Back

#92
> We strongly urge all journalists, activists, and politicians to upgrade to an iPhone that was released in the past two years with an A12 or higher CPU.

This makes no sense. The data of these VIPs is not in (more) danger due to this new jailbreak appearing. It sounds like a cheap trick to make people buy new phones.

Re: Tethered Jailbreaks Are Back

#93
post #20

Earlier quoted context omitted.

Makes sense given how they try and spin this is only good for pirates (and researchers), because they would be the only ones who would like a jailbroken device.

A decade of corporate brainwashing has convinced people that only criminals want to control the device they own.

Jailbreak is a good way to let criminals to control your phone.

Re: Tethered Jailbreaks Are Back

#94
post #92

> We strongly urge all journalists, activists, and politicians to upgrade to an iPhone that was released in the past two years with an A12 or higher CPU. This makes no sense. The data of these VIPs is not in (more) danger due to this new jailbreak appearing. It sounds like a cheap trick to make people buy new phones.

"checkm8 doesn't allow law enforcement to decrypt the phone, but it does allow them to rootkit it with 30 seconds of unattended access. Once it's unlocked by the user they'd get everything they need."

That sounds like something more than a little worrying to the listed groups of people, no?

Re: Tethered Jailbreaks Are Back

#95
post #11

Earlier quoted context omitted.

A jailbroken device allows apps to do things that a non-jailbroken device does not. I maintain my company's in-house mobile app crash reporting system and I had to remove jailbreak checks from our iOS SDK. It turned out that some of the checks were causing crashes themselves due to buggy anti-jailbreak-detection code some jailbroken devices had in place. e.g. checking whether a file could be accessed that normally iO…

Out of interest, why do you care if your users run your application on a jailbroken device? It’s been a question I’ve had for a while..

Jailbroken devices can attack application logic to cheat in multiplayer games, somewhat attack DRM systems for video content (though Fairplay isn't especially vulnerable here), gain access to chargeable features without paying for them (decompiled Spotify APKs that do not feature advertising without having to pay exist on Android and are a non-trivial revenue risk) etc etc.

In more open systems you are usually more able to run detection software for the above without sandboxing.

Re: Tethered Jailbreaks Are Back

#96
post #59

Earlier quoted context omitted.

And if a person loses the phone one month into their payment plan they still have to pay for the entire price of the phone. So you take ownership the moment you make an agreement with the company to make payments.

Payment plans seem like absolute insanity to me. Everyone I know on one is paying $100+ AUD per month perpetually since as soon as they have paid it off they get a new phone. I have found that it is insanely cheap to just buy last years phone second hand. I picked up a pixel 2 recently for $300 AUD when it was about $1000 the year before.

If one is going to buy the phone anyway, payment plans with 0% interest make a lot of sense (from the buyer's perspective).

Re: Tethered Jailbreaks Are Back

#97
post #10

Earlier quoted context omitted.

> if there's a real security risk There is, but it's not that great. You need physical access to the device and it won't be persistent (a reboot will clean it).

> You need physical access I don't understand why people keep downplaying this. The whole point of a secure phone is that the data can't be accessed even with physical access.

Threat modelling. In most models, if someone has uninterrupted physical access to a device, it's theirs.

Phones are more important in that you want to protect the assets from thieves, so we do add non-destructive physical access to our scope, but it's with a higher bug-bar. Someone being able to take your phone, compromise it, then give it back to you so you can input new assets means that a vulnerability has to be severe to be as important as a minor remote vulnerability.

Re: Tethered Jailbreaks Are Back

#98
post #90

Earlier quoted context omitted.

They also get tripped up by Apple internal devices, which as an Apple employee is quite annoying when I get locked out of a financial app.

I feel like Apple employees shouldn't be using special iPhones for personal use (out of good engineering practice; nothing special.

Who else would be the best to test new phones, software and features, and understand how they may create bugs with 3rd party apps?

In fact it’s critical to do so.

Re: Tethered Jailbreaks Are Back

#99
post #38
post #22

Earlier quoted context omitted.

For example, you could implant a hardware backdoor that monitors the touchscreen inputs

To do that, you'd need to disassemble the phone to insert your implant. That might be hard to do in the field (ie. not in a repair shop/lab setting with plenty of tools lying around). Not to mention the difficulties of designing and manufacturing an implant. How are you going to get it to fit? I don't think there's a lot of empty space inside a phone. How many variants would you need to design and carry around? I'd i…

Agreed there is a substantial difference in difficulty between the attacks. I am only speaking to the parent's point about the phone somehow previously being secure and now not being secure. The only thing that's changed is the difficulty of the attack.

There are easier physical attacks too: for example just replace the whole device with an identical one you control. Replicate the target's lock screen in software and capture their inputs.

Re: Tethered Jailbreaks Are Back

#100

Earlier quoted context omitted.

Out of interest, why do you care if your users run your application on a jailbroken device? It’s been a question I’ve had for a while..

Jailbroken devices can attack application logic to cheat in multiplayer games, somewhat attack DRM systems for video content (though Fairplay isn't especially vulnerable here), gain access to chargeable features without paying for them (decompiled Spotify APKs that do not feature advertising without having to pay exist on Android and are a non-trivial revenue risk) etc etc. In more open systems you are usually more a…

Piracy for Android doesn't require a jailbroken/rooted device.
Post reply on HN