Earlier quoted context omitted.
I was able to log in with my university credentials and get free access.
Convert the report to pdf and upload it to https://pdf.yt/
Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
11–20 of 87 posts
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#12Full text: https://pdf.yt/d/1dKWAxs03AvnYqkt
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#13Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#14Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.
Thank you very much - bookmarked. BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.
They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's just lip service and pure marketing.
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#15Earlier quoted context omitted.
Thank you very much - bookmarked. BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.
> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#16Earlier quoted context omitted.
Convert the report to pdf and upload it to https://pdf.yt/
looks like someone did http://pdf.yt/d/1dKWAxs03AvnYqkt
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#17Would bluetooth or iBeacon or Wifi be used with that, or does it need a cable, or actual button pressing, for example?
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#18Full text: https://pdf.yt/d/1dKWAxs03AvnYqkt
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#19>This is due to iOS' behavior of automatically joining networks whose name (not MAC address) it recognizes, such as “linksys” or “attwifi”. Discriminating by MAC addresses would not help at all. MAC addresses are trivial to spoof, even though they are "in hardware". It would be cool if we had a standardized trust-on-first-use cryptographic authentication model for wireless APs, like we do with SSH right now. You conn…
Of course, once you have the AP password there's a lot you can do to the network traffic anyway, but it'd still be nice if the computer would pop something up and say, "The configuration of this device does not match the known configuration - do you still want to connect?"
Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices
#20>This is due to iOS' behavior of automatically joining networks whose name (not MAC address) it recognizes, such as “linksys” or “attwifi”. Discriminating by MAC addresses would not help at all. MAC addresses are trivial to spoof, even though they are "in hardware". It would be cool if we had a standardized trust-on-first-use cryptographic authentication model for wireless APs, like we do with SSH right now. You conn…
Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…