Live data from Hacker News

Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

zdziarski.com

41–50 of 87 posts

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#41
post #9
post #4

Earlier quoted context omitted.

I was able to log in with my university credentials and get free access.

Even better. For a measly 10.000 in tuition I can access the article!

He's saying, for students, there's zero marginal cost to access it

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#42
post #16
post #11

Earlier quoted context omitted.

looks like someone did http://pdf.yt/d/1dKWAxs03AvnYqkt

Tangent: This is a good site for PDFs, immensely better than scribd. Whenever I click a link in the PDF (for eg. pg 17), the document zoomed in permanently. I cannot find a way to revert back to original zoom, even opening the link again does not help. So whoever is running the site, please look into this bug.

It appears to be a bug in pdf.js (or the PDF format itself): https://github.com/mozilla/pdf.js/issues/5064

As somebody else mentioned, you can use the arrow/triangle to display the regular viewer toolbar, and zoom out. This is obviously not ideal, but there's not much else that can be done until a fix comes from pdf.js upstream, I suppose.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#43
post #14

Earlier quoted context omitted.

Thank you very much - bookmarked. BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

I disagree...Apple's size makes it ideal for resistance - the government has been very pro-business for the last decade, and congress has been way too receptive to lobbying groups. If Apple, Google, and a few others really put some muscle into it, they could make a real difference.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#44
post #14

Earlier quoted context omitted.

Thank you very much - bookmarked. BTW, Apple is missing a great opportunity in my opinion. They don't need a ton of user data to make money and could evolve into the secure consumer device company. I see only upside for Apple if they work towards making as secure as possible devices.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

but they DO have the option of designing their hardware and services to minimize trackable data, to get as close to "zero knowledge" as possible. The government cannot force them to collect data, only share data that they have collected.

For example, there are alternatives to Dropbox that do this: http://www.theguardian.com/technology/2014/jul/17/edward-sno...

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#45
post #39
post #18

Earlier quoted context omitted.

Mods, please change the article URL to this.

The URL should IMHO be http://www.zdziarski.com/blog/?p=3441 (primary source) or even directly http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... .

I agree. We changed the url to that second link from http://www.sciencedirect.com/science/article/pii/S1742287614....

Linking directly to the pdf would go against what the author says he wants there.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#46
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it.

Is this not the case?

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#47
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it. Is this not the case?

[deleted]

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#48
post #2

Mr Zdziarski gave this talk also at the HOPE conference yesterday. It's highly recommended. Slides: http://www.zdziarski.com/blog/wp-content/uploads/2014/07/iOS... For the people wanting to secure their iphone, go to the end to the slide "Apple Configurator" and follow the described steps to disable your iphone from paring with anything.

I'm confused. Normally one cannot "pair" a device without entering the passcode to unlock it. Is this not the case?

[deleted]

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#50

I know each publisher is different, but is there a guideline amount of how much each researcher gets when they are published in such journals?

-$2000 is fairly common.

As mentioned below, authors have to pay publication fees. Most journals are for profit and closed-access, though this is starting to change somewhat. Somewhat ironically, being published in these journals is a prerequisite for how researchers actually do get paid: by grants, usually taxpayer funded.

Post reply on HN