Earlier quoted context omitted.
In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…
Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
Any iPhone can be hacked with a modified charger in under a minute
11–20 of 28 posts
Re: Any iPhone can be hacked with a modified charger in under a minute
#12With hardware access all bets are off.
Re: Any iPhone can be hacked with a modified charger in under a minute
#13Earlier quoted context omitted.
Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
For the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
Re: Any iPhone can be hacked with a modified charger in under a minute
#14Earlier quoted context omitted.
Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
For the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
Re: Any iPhone can be hacked with a modified charger in under a minute
#15Re: Any iPhone can be hacked with a modified charger in under a minute
#16Earlier quoted context omitted.
For the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
I think you underestimate how willing people are to share chargers. If you make one of these malicious chargers, and mock it up to look similar enough to an Apple one, I bet you could compromise a decent number of phones just by hanging out in a popular place (e.g. a coffee shop, or an airport) and making your charger available to folks.
Re: Any iPhone can be hacked with a modified charger in under a minute
#17Earlier quoted context omitted.
For the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
I think you underestimate how willing people are to share chargers. If you make one of these malicious chargers, and mock it up to look similar enough to an Apple one, I bet you could compromise a decent number of phones just by hanging out in a popular place (e.g. a coffee shop, or an airport) and making your charger available to folks.
Re: Any iPhone can be hacked with a modified charger in under a minute
#18Earlier quoted context omitted.
In almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be expl…
Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
Re: Any iPhone can be hacked with a modified charger in under a minute
#19Earlier quoted context omitted.
Please stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
For the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
Re: Any iPhone can be hacked with a modified charger in under a minute
#20With hardware access all bets are off.
Yeah, but I think this is a bit worse than that. If a faulty ethernet driver lets you compromise a laptop just by plugging it into a malicious network, that's a legitimate vulnerability, not really a case of "well, they had physical access". USB may be customarily treated as more trusted than ethernet, but there are clearly still scenarios where untrusted people may be able to send you USB messages.