According to him the exploit chain was likely worth in the region of a 8-digit dollar value.
¹ https://en.wikipedia.org/wiki/Felix_von_Leitner
I guess somebody is going to get fired.
291–300 of 433 posts
According to him the exploit chain was likely worth in the region of a 8-digit dollar value.
¹ https://en.wikipedia.org/wiki/Felix_von_Leitner
I guess somebody is going to get fired.
Earlier quoted context omitted.
Ahem, Snowden, PRISM anyone?
Ahem, you mean you have a single example, from a decade ago, one where Apple was hardly a key player (hence why Apple didn’t sign onto PRISM until half a decade after Yahoo, Microsoft, Google, et all), as conclusive evidence of “eagerness to partner with spy agencies”, despite numerous public cases where they’ve done the opposite… got it!
"We already know Apple cooperated with the spy agencies behind the publics back"?
Coresight is not some backdoor - it's a debug feature of all ARM CPU's. This looks like a necessary extension to coresight to work with Apples memory protection stuff. Even though no public documentation exists, I'm sure thousands of Apple engineers have access to a modded gdb or other tooling to make use of it.
Earlier quoted context omitted.
Ahem, you mean you have a single example, from a decade ago, one where Apple was hardly a key player (hence why Apple didn’t sign onto PRISM until half a decade after Yahoo, Microsoft, Google, et all), as conclusive evidence of “eagerness to partner with spy agencies”, despite numerous public cases where they’ve done the opposite… got it!
That makes sense, would you agree to the revised statement: "We already know Apple cooperated with the spy agencies behind the publics back"?
Earlier quoted context omitted.
There are different levels of secret. I would never leak a normal company secret. But a national security secret is a different story.
I do wonder if the people earning millions of dollars a year think the same way however. Considering how compartmentalized Apple is it would not take many people to be in on this.
Earlier quoted context omitted.
My adjacent conspiracy theory is that the NSA and other state agencies do both original research and pay hackers for exploits that Apple hasn’t yet discovered.
They have the budget to do both easily. Like how the NRO used to design and launch satellites that cost more than aircraft carriers but are now working closely with private companies like Maxar to find more economical solutions. https://www.maxar.com/press-releases/nro-awards-maxar-a-10-y...
Told you so.
edit: The fact that this obvious statement gets upvoted above the apple backdoor on 22:40 of the talk also says alot.
edit1: https://imgur.com/a/82JV7I9
[flagged]
I'd disagree with this. Apple execs surely know if this information gets leaked they're losing 30% market cap in a single day, why would they risk something like that when administrations change every 4-8 years?
Compare with minute 22:40 of the talk
As well as https://imgur.com/a/82JV7I9
What are the chances this MMIO register could have been discovered by brute force probing every register address? Mere differences in timing could have indicated the address was a valid address, and then the hash could perhaps have been brute forced too since it is effectively a 20 bit hash.
The part that's less easily explained is how they were able to reconstruct a custom sbox table to execute the debug code. That's where the "insider threat" insinuations are strongest, but personally I'm not convinced that it precludes any number of other plausible explanations. For example, the attackers could have extracted the sbox from: older firmwares, OTA update patches, pre-release development devices (probably purchasable on ebay at some points), iOS beta releases, or a bunch of other leaky vectors.
The researcher basically says "I couldn't find this sbox table in any other binary where I looked for it." Well, that's not necessarily surprising since it appears to be Apple specific and thus there are a limited number of binaries where it might have appeared. And as the researcher notes, this includes now unpublished binaries that might have been mistakenly released. It's totally plausible that the attackers got lucky at some point while they were systematically sniffing for this sort of leak, and that the researcher is unlikely to have the same luck any time soon.