Live data from Hacker News

Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

blogs.forbes.com

61–70 of 74 posts

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#61
post #59
post #48

Earlier quoted context omitted.

I think the issue is not their security team, who seem to do quite a good job securing iOS (which I'd consider one of, if not the most, secure consumer operating systems out there). The issue is that securing an OS is hard . It's hard to make it that someone with physical access to the device cannot just run code on it, which is what jailbreaking (in its purest form, on iOS devices) is.

Arbitrary code execution is different than requiring physical access to the device. The JailbreakMe site could have run malicious code and it could have spread itself and run without the user knowing.

I was talking about the majority of jailbreaks, not JailbreakMe. Most jailbreaks are done at the low-level bootloader level, which does require physical access to the device (as well as pressing a bunch of buttons in a certain way); and even that doesn't get you access to the keychain or anything it protects.

Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it could not "spread itself": it was a browser exploit (although it would be possible to run without the user knowing).

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#62
post #61
post #59

Earlier quoted context omitted.

Arbitrary code execution is different than requiring physical access to the device. The JailbreakMe site could have run malicious code and it could have spread itself and run without the user knowing.

I was talking about the majority of jailbreaks, not JailbreakMe. Most jailbreaks are done at the low-level bootloader level, which does require physical access to the device (as well as pressing a bunch of buttons in a certain way); and even that doesn't get you access to the keychain or anything it protects. Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it c…

> Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it could not "spread itself": it was a browser exploit (although it would be possible to run without the user knowing).

It could certainly spread. Maybe it could SMS a link to a malicious download to your most frequently contacted contacts? Being able to run arbitrary code on a device that knows how to contact all your friends certainly introduces some vectors for attack.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#63
post #8

Jailbreakme is an amazingly elegant tool. Although I seriously doubt they will, Apple should definitely hire him. His products show that he understands design as well as anyone on their payroll now. That combined with his obvious coding skills make him the ideal Apple engineer.

> 'His products show that he understands design as well as anyone on their payroll now.' He designed none of the interface. > '... his obvious coding skills ...' A lot of the time, a person's coding skills are judged by how readable their code is, and how well they utilize SCM. Also, to be an Apple engineer you want extensive experience with Objective-C. https://github.com/comex/star_ Now I don't mean to say comex is…

It's worth mentioning that geohot was, by no means, a fabulous programmer - sure, he's done a lot of great reverse engineering and security work, but if you look at his code, it was both advanced and sloppy. However, Facebook hired him to work on product development, even though he's known to not be much of a programmer.

Comex may not fit the profile of an Apple engineer, but I think he'd still do a damn good job as one.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#64
The kid goes to my school; we're both in the CS department. I met him once, and I saw him around the department a lot while he was still here. I don't know him, but from what I've seen, it's no surprise he hasn't found an internship: the kid is incredibly anti-social. Not to mention that being dismissive of other people in your first year isn't exactly the best way to build up connections.

Before I saw this article, I honestly had no idea he was Comex. I could tell he was brilliant, but that's pretty awesome.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#65

The kid goes to my school; we're both in the CS department. I met him once, and I saw him around the department a lot while he was still here. I don't know him, but from what I've seen, it's no surprise he hasn't found an internship: the kid is incredibly anti-social. Not to mention that being dismissive of other people in your first year isn't exactly the best way to build up connections. Before I saw this article,…

I don't think you should levy anonymous attacks on peoples personalities

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#66
post #19

I have no clue how there is even a question about the legality of using your own hardware for whatever you want. I could "crash cell phone towers" with my car, but that doesn't give Ford the right to weld my hood shut. Seriously, how is this acceptable to anyone?

Is there such a question?

If you jailbreak but continue to make phonecalls, use the AppStore, etc. are you in breach of any of the contracts you signed or licenses you agreed to?

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#67
post #62
post #61

Earlier quoted context omitted.

I was talking about the majority of jailbreaks, not JailbreakMe. Most jailbreaks are done at the low-level bootloader level, which does require physical access to the device (as well as pressing a bunch of buttons in a certain way); and even that doesn't get you access to the keychain or anything it protects. Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it c…

> Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it could not "spread itself": it was a browser exploit (although it would be possible to run without the user knowing). It could certainly spread. Maybe it could SMS a link to a malicious download to your most frequently contacted contacts? Being able to run arbitrary code on a device that knows how to contact a…

FYI, it is a PDF-based exploit, meaning all users have to do is open a malicious PDF.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#68
post #34

So much misinformation. Apple "rushed to patch the security opening" because IT'S A SECURITY FLAW that allows unrestricted code execution via a website. That's a pretty huge problem; shouldn't it be fixed right away? "After Allegra released JailbreakMe 2 last year, Apple upped its game another notch, randomizing the location of code in memory so that hackers can’t even locate commands to hijack them." Another securit…

"The tool isn’t intended for theft or vandalism: It merely lets users install any application they want on their devices. But jailbreaking, as the practice is called, violates Apple’s obsessive control of its gadgets and demonstrates software holes that could be exploited later by less benevolent hackers."

I thought that was pretty clear.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#69
post #8

Jailbreakme is an amazingly elegant tool. Although I seriously doubt they will, Apple should definitely hire him. His products show that he understands design as well as anyone on their payroll now. That combined with his obvious coding skills make him the ideal Apple engineer.

I'm not sure hiring a cracker like Comex is an easy decision for any big corporation, especially for a company as tidy as Apple. Thanks to him they're probably spending big bucks on legal fees and losing valuable sleeping hours reviewing those exploits (which is a good thing anyway). Not to mention PR headaches he has caused. OTOH, Comex work helps boost iPhone sales among techies. I know people who chose Apple over Android just because they could jailbreak it.

It probably wouldn't be an easy decision for Comex either... I recall that hacker that turned down Sony's offer. What could happen to your hacker freedom once you're at your employer's mercy? And if you leave Apple someday, forget about jailbreaking any other Apple device for as long as you live due NDA's and all the legal stuff he would have sign.

Re: Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple

#70
post #48

Earlier quoted context omitted.

Recent history proves that Apple is not capable of solving the jail breaking problems with their current security organization. If they were, then their Operating Systems wouldn't be broken so quickly.

I think the issue is not their security team, who seem to do quite a good job securing iOS (which I'd consider one of, if not the most, secure consumer operating systems out there). The issue is that securing an OS is hard . It's hard to make it that someone with physical access to the device cannot just run code on it, which is what jailbreaking (in its purest form, on iOS devices) is.

Actually, in the long run it is impossible to make it that someone with physical access to the device cannot run arbitrary code on it.

See the first of the 10 Immutable Laws of Security: http://technet.microsoft.com/en-us/library/cc722487.aspx

Post reply on HN