Live data from Hacker News

Analysis of Obfuscation Techniques Found in Apple FairPlay

nicolo.dev

51–56 of 56 posts

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#51

Earlier quoted context omitted.

Users love this stuff. It lets them buy cheap consoles that are sold below cost and subsidised by game royalties. Heavy gamers subsidise light gamers, and both can effectively "pay off" the true cost of the hardware over time as they buy titles. So it's a bit like zero-interest credit. Also it eliminates cheating in multiplayer games, and users love that too. And finally it stops gamers who play by the rules and buy…

Consider privacy. One might say "Users love this stuff. They get complex and effective services for free, all in exchange for contributing their data towards ads. Purchasers and advertisers subsidize light users who just consume the content." And yet, we got laws like GDPR on the ideological basis that personal data is above the concept of "market" and about the individual, period. Your business model be damned. The…

These same platform controls allow Apple to restrict user data collection from apps. Meanwhile: the notion of a "digital free society" isn't a thing.

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#52

Earlier quoted context omitted.

It lets you detect if the user is running a vulnerable kernel. Apple's stack is pretty secure. When was the last iPhone jailbreak? I don't follow it closely as I'm not an iPhone user, but it feels like a long time ago now. And if an exploit is found, they can just revoke that kernel version. Apps can then ask users to apply the update to regain access to their streams.

exploits are just kept private by bad actors nowadays. Apple now gets the worst of both worlds, the harmless jailbreaking scene is dying but the bad actors are still in full force.

How is that the worst of both worlds? The harmless jailbreak world also empowers bad actors.

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#53
post #51

Earlier quoted context omitted.

Consider privacy. One might say "Users love this stuff. They get complex and effective services for free, all in exchange for contributing their data towards ads. Purchasers and advertisers subsidize light users who just consume the content." And yet, we got laws like GDPR on the ideological basis that personal data is above the concept of "market" and about the individual, period. Your business model be damned. The…

These same platform controls allow Apple to restrict user data collection from apps. Meanwhile: the notion of a "digital free society" isn't a thing.

I'd much prefer governments use their force of law to make those tracking practices impossible (for anything that isn't an outright criminal enterprise) than a private entity making them technically difficult.

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#54
post #48

Earlier quoted context omitted.

> We use IDA for convenience in this article, although we must be especially careful when importing the binary into other tools (we will explain why at the end of the article) Forgive me if I missed this being explained - I was curious what the reasoning for this was and I didn't see it! Could you elaborate? :)

Ops! Forgot to write about it (otherwise it would be so long). I did not mention the tools, but I was mainly referring to Hopper Decompiler/Disassembler (definitely no no for me). Altough it seemed the natural choice for reverse engineering macOS applications and daemons, it failed disastrousely on reverse engineering fairplayd. This is where obfuscation is really good at: feeling pain. Hopper tried to disassemblate…

So mainly just Ghidra & Hopper were successfully tripped up by fairplayd - thanks for the explanation!

Great article overall, thanks for taking the time to write it up.

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#55
post #54

Earlier quoted context omitted.

Ops! Forgot to write about it (otherwise it would be so long). I did not mention the tools, but I was mainly referring to Hopper Decompiler/Disassembler (definitely no no for me). Altough it seemed the natural choice for reverse engineering macOS applications and daemons, it failed disastrousely on reverse engineering fairplayd. This is where obfuscation is really good at: feeling pain. Hopper tried to disassemblate…

So mainly just Ghidra & Hopper were successfully tripped up by fairplayd - thanks for the explanation! Great article overall, thanks for taking the time to write it up.

Ghidra was somehow usable, I got several crashes with Hopper. One question for more expert people than me: does Hopper employ any telemetry inside its demo version? Some issues I discovered were fixed in two days and I did not report them.

Re: Analysis of Obfuscation Techniques Found in Apple FairPlay

#56
post #52

Earlier quoted context omitted.

exploits are just kept private by bad actors nowadays. Apple now gets the worst of both worlds, the harmless jailbreaking scene is dying but the bad actors are still in full force.

How is that the worst of both worlds? The harmless jailbreak world also empowers bad actors.

I never beleived that PR argument
Post reply on HN