Live data from Hacker News

Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

zdziarski.com

61–70 of 87 posts

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#61
post #16

Earlier quoted context omitted.

Tangent: This is a good site for PDFs, immensely better than scribd. Whenever I click a link in the PDF (for eg. pg 17), the document zoomed in permanently. I cannot find a way to revert back to original zoom, even opening the link again does not help. So whoever is running the site, please look into this bug.

It appears to be a bug in pdf.js (or the PDF format itself): https://github.com/mozilla/pdf.js/issues/5064 As somebody else mentioned, you can use the arrow/triangle to display the regular viewer toolbar, and zoom out. This is obviously not ideal, but there's not much else that can be done until a fix comes from pdf.js upstream, I suppose.

Turns out it's a "feature" of the PDF format.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#62
post #59
post #14

Earlier quoted context omitted.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

There's another reason this won't happen: very few users really care. If users really wanted it and clamored for it and showed a clear market preference for secure and privacy-respecting companies, then you might get somewhere.

Let's imagine a non-zero subset of users who care, today.

What would they buy, today, in order to "show a clear market preference"?

It's a bit difficult to show statistical evidence of people making choices which are unavailable to them.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#63
post #50

Earlier quoted context omitted.

-$2000 is fairly common. As mentioned below, authors have to pay publication fees. Most journals are for profit and closed-access, though this is starting to change somewhat. Somewhat ironically, being published in these journals is a prerequisite for how researchers actually do get paid: by grants, usually taxpayer funded.

Is it also true that some organisations also pay their employees if they publish papers, I've heard this happens in the security field.

It doesn't happen in physics and mathematics. On the other hand you will probably be fired if you don't publish...

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#64
post #58

Earlier quoted context omitted.

Yes, but one issue is that you could be pressured into pairing the device. Or someone can brute force the passcode to access the pairing UI. The slides mention a way to bypass pairing, but I don't think ever mentioned how.

Apple can boot the device over USB using a custom image that doesn't require the passcode. Other people can't because it needs to be signed with Apple's key in order to run.

Got it. But if you say "don't allow pairing" they're SOL from a software perspective? I find that hard to believe... but either way, who knows really.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#65
post #20
post #19

Earlier quoted context omitted.

Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…

OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.

I guess this is to combat password stealing attempts in particular, and not AP spoofing in general?

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#66
post #20
post #19

Earlier quoted context omitted.

Yeah, I've been shocked by how easy it is to get a brand new router and set it up with the same SSID and password and every device I have auto-connects like it's the same thing. If you have the AP password, it's trivial to set up a fake second router in the same vicinity (you don't even have to touch the original one) with a stronger signal and have everyone connect through your gateway. Of course, once you have the…

OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.

I guess this is to combat password stealing attempts in particular, and not AP spoofing in general, since you could easily make the new AP WPA2?

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#67
post #14

Earlier quoted context omitted.

> evolve into the secure consumer device company They don't have this option. They are too big to not cooperate the US law enforcement and intelligence communities. They must cooperate, it's given. There are just way too many pressure points that can be exploited to make them cooperate, even against their will. If they start selling themselves as a secure and trustworthy device manufacturer you can rest assured it's…

I disagree...Apple's size makes it ideal for resistance - the government has been very pro-business for the last decade, and congress has been way too receptive to lobbying groups. If Apple, Google, and a few others really put some muscle into it, they could make a real difference.

They are doing this already, but you're not going to see a more secure software stack until the laws change.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#68
post #29

Earlier quoted context omitted.

yeah, if your device wasn't supervisioned before it would clean install - i guess but i haven't tried and/or checked otherwise if you can than reapply your backup.

I found a way: you can apply the restriction to a non-supervised device, which simplifies the process. You don't need to re-install or wipe. Just create a profile with the restrictions, then follow the instructions at: http://support.apple.com/kb/HT5833 (Edit to add: It's actually unclear if the non-pairing restriction gets applied when using this method, it doesn't seem to get listed in the profile details once on t…

It does not. The Allow pairing with non-Configurator hosts requires that the device be supervised.

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#69
post #40
post #36

Earlier quoted context omitted.

I wasn't suggesting that, obviously. I was trying to be helpful and point out that students have free access.

OT: Technically, it is not free access. You (or at public institutions, the general public) paid for your access … in discussions on open access, I often learn that many researchers, scientists etc. are under the impression that they already have open access although the simply get routed around paywalls because they use IP addresses of their paying institutions.

Really? Universities don't have a bulk subscription plan or something?

Re: Identifying backdoors, attack points, and surveillance mechanisms in iOS devices

#70
post #66
post #20

Earlier quoted context omitted.

OSX and I assume iOS does do detection of this. If you connect to an AP that was WPA2 encrypted in the past, and has the same name but no encryption now, it gives you a big scary warning and bails out.

I guess this is to combat password stealing attempts in particular, and not AP spoofing in general, since you could easily make the new AP WPA2?

If have to look it up, but I don't think the AP would get the plaintext password during the WPA2 key exchange.
Post reply on HN