Live data from Hacker News

Tethered Jailbreaks Are Back

blog.trailofbits.com

111–120 of 122 posts

Re: Tethered Jailbreaks Are Back

#111
post #102
post #26

Earlier quoted context omitted.

Ha, I wonder if an attacker could use this bug to prevent or fake the rebooting process by changing the behavior of the lock/volume buttons when they’re held. I know there’s also a “hard reset” you can do with volume up -> volume down -> power, not sure if that works at a lower level.

Yes, an attacker using checkm8 could do that if they had a separate exploit for persistence. That exploit would be in iOS and take over at a later point in the boot process, and it would be possible for Apple to patch it with an iOS update. Those bugs are hard to find, but there have been dozens discovered in the past.

I’m a little confused, which part of my comment would require persistence? I was suggesting a lulzy payload that would prevent the user from _actually_ restarting their device by changing the behavior of the power button. As a means of bypassing the “just restart your phone every time you use it” countermeasure.

Re: Tethered Jailbreaks Are Back

#112

Earlier quoted context omitted.

iOS doesn't sent your every click to Google? https://digitalcontentnext.org/wp-content/uploads/2018/08/DC...

as the paper notes, ios itself doesn’t send much to google. it’s primarily installed apps that send data to google, and that’s primarily advertising related. google apps will additionally send all your location data to google. moral of the story: don’t install any google apps and limit the number of apps you install.

I'm not going to ruin my phone experience just for that. Why should I care that my apps have telemetry for ads. It keeps them free.

Re: Tethered Jailbreaks Are Back

#113
post #90

Earlier quoted context omitted.

I feel like Apple employees shouldn't be using special iPhones for personal use (out of good engineering practice; nothing special.

Who else would be the best to test new phones, software and features, and understand how they may create bugs with 3rd party apps? In fact it’s critical to do so.

If that's your goal, shouldn't you be using a customer install?

Re: Tethered Jailbreaks Are Back

#114

Are there potential disadvantages involved with “demotion” to enable JTAG? From what I understand the process is permanent (eFUSE?) but it seems like a fun thing to play around with

Jailbreaking is software based and doesn't actually void your warranty. Demotion will.

Re: Tethered Jailbreaks Are Back

#115
post #30
post #12

Earlier quoted context omitted.

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

I reboot my phone once in a blue moon, but my phone reboots itself roughly every other day (usually because I space on charging it). Am I that unusual, or is "the phone is rarely going to reboot" not really a reliable predicate for attackers?

Only on update, and only if the update requires it.

Re: Tethered Jailbreaks Are Back

#116
post #12

Earlier quoted context omitted.

It certainly will _feel_ persistent if you're successfully attacked with this technique. If your iOS software is swapped out for a version with a backdoor, then the attacker will have collected your passwords and authentication tokens to services you use. If you reboot to clear the backdoor (and let's be honest: no one reboots their phones), then you won't also "clear" your attacker's memory of all your passwords.

If your iOS version is swapped out with one that is backdoored, it won’t boot after you reboot it without using this boot loader exploit on a computer again. This makes you ever so slightly more vulnerable to an evil maid attack, but we don’t even have a jailbreak yet using this so it’s to be determined how it all shakes out.

I believe a reboot will cause you to boot stock iOS again.

Re: Tethered Jailbreaks Are Back

#117
post #100

Earlier quoted context omitted.

Jailbroken devices can attack application logic to cheat in multiplayer games, somewhat attack DRM systems for video content (though Fairplay isn't especially vulnerable here), gain access to chargeable features without paying for them (decompiled Spotify APKs that do not feature advertising without having to pay exist on Android and are a non-trivial revenue risk) etc etc. In more open systems you are usually more a…

Piracy for Android doesn't require a jailbroken/rooted device.

It only requires one jailbroken device on iOS. Or, if you're using the right tools, none.

Re: Tethered Jailbreaks Are Back

#118
post #96

Earlier quoted context omitted.

Payment plans seem like absolute insanity to me. Everyone I know on one is paying $100+ AUD per month perpetually since as soon as they have paid it off they get a new phone. I have found that it is insanely cheap to just buy last years phone second hand. I picked up a pixel 2 recently for $300 AUD when it was about $1000 the year before.

If one is going to buy the phone anyway, payment plans with 0% interest make a lot of sense (from the buyer's perspective).

I suspect that for a lot of people, without the payment plan they would not buy anyway since they can't afford to buy these outrageously expensive devices outright.

Re: Tethered Jailbreaks Are Back

#119
post #102

Earlier quoted context omitted.

Yes, an attacker using checkm8 could do that if they had a separate exploit for persistence. That exploit would be in iOS and take over at a later point in the boot process, and it would be possible for Apple to patch it with an iOS update. Those bugs are hard to find, but there have been dozens discovered in the past.

I’m a little confused, which part of my comment would require persistence? I was suggesting a lulzy payload that would prevent the user from _actually_ restarting their device by changing the behavior of the power button. As a means of bypassing the “just restart your phone every time you use it” countermeasure.

Would not work, as this is indeed a lower-level function.

Re: Tethered Jailbreaks Are Back

#120

Earlier quoted context omitted.

You can already assume that states are sitting on exploits that they've found or bought, and that they can compel companies to provide some form of access via NSLs or secret courts.

only more advanced states.

Nah, anyone with a pile of money can buy exploits and hire professionals to discover them.

Kingdoms in the desert have had access to root certificates for almost a decade now.

Post reply on HN