Live data from Hacker News

Any iPhone can be hacked with a modified charger in under a minute

geek.com

1–10 of 28 posts

Re: Any iPhone can be hacked with a modified charger in under a minute

#2
It's interesting how the progress of iPhone hacks is mirroring that of the PSP homebrew scene 5 or 6 years ago. First there were a bunch of easy to use vulnerabilities or hidden features in apps (like the hidden browser in WipeOut)that provided functions that were offered natively in future versions of the OS. Then the hacking scene moved to OS vulnerabilities. As Sony locked down the platform tighter and tighter, people moved to hardware, using modded batteries to boot the PSP in some kind of troubleshooting mode.

Eventually, both Sony and the hackers kind of lost interest, I think -- I haven't kept up with things, TBH. That said, Sony had the PS Vita to move to, but I don't see the iPhone changing significantly in the next few years (risky words, I know, but I'll be happy if proven wrong).

Re: Any iPhone can be hacked with a modified charger in under a minute

#3
Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. That means that it's unlikely that people will have a perennial, easy jailbreak going forward from this source.

Re: Any iPhone can be hacked with a modified charger in under a minute

#4

Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. That means that it's unlikely that people will have a perennial, easy jailbreak going forward from this source.

>Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed.

I wouldn't consider that unfortunate. Responsible disclosure should be praised!

Re: Any iPhone can be hacked with a modified charger in under a minute

#6
post #4

Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. That means that it's unlikely that people will have a perennial, easy jailbreak going forward from this source.

>Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. I wouldn't consider that unfortunate. Responsible disclosure should be praised!

In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be exploited against my phone is if I chose to jailbreak it.

Re: Any iPhone can be hacked with a modified charger in under a minute

#7
post #5

With hardware access all bets are off.

Yeah, but I think this is a bit worse than that.

If a faulty ethernet driver lets you compromise a laptop just by plugging it into a malicious network, that's a legitimate vulnerability, not really a case of "well, they had physical access".

USB may be customarily treated as more trusted than ethernet, but there are clearly still scenarios where untrusted people may be able to send you USB messages.

Re: Any iPhone can be hacked with a modified charger in under a minute

#8
post #4

Earlier quoted context omitted.

>Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. I wouldn't consider that unfortunate. Responsible disclosure should be praised!

In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…

Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.

Re: Any iPhone can be hacked with a modified charger in under a minute

#9
post #4

Earlier quoted context omitted.

>Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. I wouldn't consider that unfortunate. Responsible disclosure should be praised!

In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…

> insecure systems are preferable (as a user)

No they’re not. Religious issues should never come before security.

Re: Any iPhone can be hacked with a modified charger in under a minute

#10
post #9

Earlier quoted context omitted.

In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…

> insecure systems are preferable (as a user) No they’re not. Religious issues should never come before security.

What? I am not speaking about a religious desire for freedom. I'm speaking of the practical pros and cons of wanting to use a system I own in a certain way and not being able to, versus a miniscule risk of a certain attack vector being exploited.

Did the irony of calling my point of view religious while implying that security overrides all other preferential considerations escape you?

Post reply on HN