Earlier quoted context omitted.
That's fine. I'm more concerned that the (replacement) hardware on my own device is not malicious, than I am with the hardware on other devices that are already outside my control. My trust model doesn't include them to begin with. And to the extent that my OS trusts those devices, at least any bugfixes can be pushed via software update. As the article notes, there is a simple way to stop this attack, which is to dis…
> That's fine. I'm more concerned that the (replacement) hardware on my own device is not malicious, than I am with the hardware on other devices that are already outside my control. You are more concerned with someone opening your iPhone and putting a replacement malicious part than with someone pwning your iPhone with a $5 wireless device while in his car just driving by ? Your threat model is upside down.
Flipper Zero can be used to crash iPhones running iOS 17
11–20 of 38 posts
Re: Flipper Zero can be used to crash iPhones running iOS 17
#12Earlier quoted context omitted.
I would be very concerned with someone pwning my phone with a $5 wireless device, but that's not what's happening here. This is a DoS attack. It could never be perfectly mitigated, as long as any mitigation depends on the (arguably) fundamentally impossible task of verifying an external device is a "real" Apple device. It's possible to design security protocols that allow me to verify my device is a real Apple device…
> This is a DoS attack. It could never be perfectly mitigated Bullshit. Flooding the waves with radio interference (something that Bluetooth is particularly resistant to) would at most "deny service" of another device trying to connect to my iPhone through Bluetooth. It should NOT deny service of the _entire_ iPhone, which is what is discussed here. This is 100% preventable crap. > the (arguably) fundamentally imposs…
It also does not qualify as "pwning" your device, at least for my interpretation of the word "pwn."
Re: Flipper Zero can be used to crash iPhones running iOS 17
#13Earlier quoted context omitted.
> This is a DoS attack. It could never be perfectly mitigated Bullshit. Flooding the waves with radio interference (something that Bluetooth is particularly resistant to) would at most "deny service" of another device trying to connect to my iPhone through Bluetooth. It should NOT deny service of the _entire_ iPhone, which is what is discussed here. This is 100% preventable crap. > the (arguably) fundamentally imposs…
I agree with you, but that doesn't negate what I said about this being correctable in software. Whereas if someone implants a malicious HSM in my iPhone, or a screen that has a secondary chip connected to it recording everything I touch, then that's not correctable in software. It also does not qualify as "pwning" your device, at least for my interpretation of the word "pwn."
Re: Flipper Zero can be used to crash iPhones running iOS 17
#14Re: Flipper Zero can be used to crash iPhones running iOS 17
#15Earlier quoted context omitted.
I agree with you, but that doesn't negate what I said about this being correctable in software. Whereas if someone implants a malicious HSM in my iPhone, or a screen that has a secondary chip connected to it recording everything I touch, then that's not correctable in software. It also does not qualify as "pwning" your device, at least for my interpretation of the word "pwn."
Your threat model is still ridiculously upside down. You are literally arguing that you are more worried about the possibility that someone subjects you to some type of maid attack (which requires an almost implausible level of dedication) rather than someone with a 5$ atmel chip claiming to be an Apple TV, automatically pairing with your device, and afterwards doing god knows what with it (including leaking more dat…
I can't opt out of a hardware attack once a malicious repair shop has replaced a critical module in my phone with their own.
Like I said, I'm more concerned with the latter. It doesn't mean I'm not concerned about attacks from external devices too.
Re: Flipper Zero can be used to crash iPhones running iOS 17
#16Earlier quoted context omitted.
Your threat model is still ridiculously upside down. You are literally arguing that you are more worried about the possibility that someone subjects you to some type of maid attack (which requires an almost implausible level of dedication) rather than someone with a 5$ atmel chip claiming to be an Apple TV, automatically pairing with your device, and afterwards doing god knows what with it (including leaking more dat…
I'm assuming I can opt-into the threat, i.e. it's possible for me to disable Bluetooth to remove my exposure to this class of attacks. When I turn on my WiFi I know that I'm subjecting myself to de-auth attacks, for example. I can't opt out of a hardware attack once a malicious repair shop has replaced a critical module in my phone with their own. Like I said, I'm more concerned with the latter. It doesn't mean I'm n…
So apparently you forever disable Bluetooth out of concern but at the same time think it is unavoidable to leave your iPhone unattended at random repair shops? At least the maid stuff (even if astronaut-level engineering) is remotely plausible.
Re: Flipper Zero can be used to crash iPhones running iOS 17
#17Earlier quoted context omitted.
Your threat model is still ridiculously upside down. You are literally arguing that you are more worried about the possibility that someone subjects you to some type of maid attack (which requires an almost implausible level of dedication) rather than someone with a 5$ atmel chip claiming to be an Apple TV, automatically pairing with your device, and afterwards doing god knows what with it (including leaking more dat…
I'm assuming I can opt-into the threat, i.e. it's possible for me to disable Bluetooth to remove my exposure to this class of attacks. When I turn on my WiFi I know that I'm subjecting myself to de-auth attacks, for example. I can't opt out of a hardware attack once a malicious repair shop has replaced a critical module in my phone with their own. Like I said, I'm more concerned with the latter. It doesn't mean I'm n…
Re: Flipper Zero can be used to crash iPhones running iOS 17
#18Earlier quoted context omitted.
> This is a DoS attack. It could never be perfectly mitigated Bullshit. Flooding the waves with radio interference (something that Bluetooth is particularly resistant to) would at most "deny service" of another device trying to connect to my iPhone through Bluetooth. It should NOT deny service of the _entire_ iPhone, which is what is discussed here. This is 100% preventable crap. > the (arguably) fundamentally imposs…
I agree with you, but that doesn't negate what I said about this being correctable in software. Whereas if someone implants a malicious HSM in my iPhone, or a screen that has a secondary chip connected to it recording everything I touch, then that's not correctable in software. It also does not qualify as "pwning" your device, at least for my interpretation of the word "pwn."
“My house is on fire, but that is easily correctable by the fire department using water, a cheap and widely available commodity. The real concern is alien abductions in my neighborhood. We are defenseless against these!”
> It also does not qualify as "pwning" your device, at least for my interpretation of the word "pwn."
Random people on the same train as me being able to crash my phone fits my definition of “pwned”. And so does me having to use wired headphones as a countermeasure.
Re: Flipper Zero can be used to crash iPhones running iOS 17
#19Re: Flipper Zero can be used to crash iPhones running iOS 17
#20Earlier quoted context omitted.
But your iPhone trusts these devices. > there is a simple way to stop this attack, which is to disable bluetooth This doesn't work, I've already tried it with my iPhone and a friend's Flipper.
Interesting. Turning bluetooth off via settings doesn't mitigate it? What about disabling AirDrop and Find My?